---
title: LastPass Users Targeted by Vishing Attackers
metaTitle: "Lastpass Users Targeted by Vishing Attackers"
description: "Scammers are employing vishing in a multi-step, hybrid phone-and-email attack to gain full access to victims' multi-factor authentication accounts."
slug: lastpass-users-targeted-by-vishing-attackers
date: "2024-04-19T21:00:00-05:00"
image:
  src: "https://cdn.securelogix.dev/slx/images/lastpass-users-targeted-by-vishing-attackers.webp"
  alt: A woman entering a password into a laptop.
sourcePublisher:
  name: HelpNet Security
  url: www.helpnetsecurity.com
sourceArticle:
  url: "https://www.helpnetsecurity.com/2024/04/19/lastpass-vishing/"
tags: [Smishing, Spoofing, Vishing]
status: published
---

The CryptoChameleon phishing kit is being leveraged by vishing attackers looking to trick LastPass users into sharing their master password.

“Initially, we learned of a new parked domain and immediately marked the website for monitoring should it go live and start serving a phishing site intended to imitate our login page or something similar. Once we identified that this site went active and was being used in a phishing campaign against our customers, we worked with our vendor to take down the site,” LastPass intelligence analyst Mike Kosak explained.

The site has been taken down, but the company expects others to pop up quickly, and is thus warning users to be wary of attackers calling them up and posing as a company representative...
