Fake password-manager alerts could put your vault at risk
You open your inbox and see a message about updated security policies. Nothing about it screams scam. The email looks polished, the wording sounds official and the button promises a quick way to review the changes. That is exactly what makes it dangerous.
LastPass is warning users about a newly identified phishing campaign that uses lookalike domains and a fake DocuSign page to lure people into downloading suspicious software.
The good news is that LastPass says its systems were not affected.