Добавить новость
Новости сегодня

Новости от TheMoneytizer

LastPass warns of a new phishing campaign involving death certificates and a nefarious email that demands you reply to it if you're not dead

If you've recently been informed that a death certificate is being used to get into your LastPass account, you have fallen victim to bad actors.

LastPass, one of the most popular password manager providers, has recently posted a blog detailing a deceptive new scam that claims a death certificate has been uploaded on your behalf (via BleepingComputer). The scam claims that another family member is attempting to access your LastPass account via the death certificate, and "if you have not passed away and believe that this is a mistake, please reply to this email with STOP."

Replying to this fake email, according to Lastpass, will cause the scammers to create a fake case and ID number, then redirect you to a site where you're asked to reset your password. As you might be able to guess, the site recipients are sent to is a fake, designed to capture a user's email address and password details via a dummy form, which is then used to gain access to your LastPass account.

LastPass claims that the creator of this scam has gone so far as to call some recipients, asking them to reply to the email and go through the website they've set up. The URL users are directed to has been linked by Google Threat Intelligence with the cybercriminal organisation CryptoChameleon. That same group were reportedly behind a LastPass phishing kit in April last year.

If you have been sent this email, you can forward any details to abuse@lastpass.com, and, as always, checking the email sender thoroughly and cross-referencing it with emails present on official websites is one of the best ways of avoiding scams.

(Image credit: LastPass)

A bad actor getting access to your LastPass account is a particular problem, as your password manager will have access to login details, among the sites you have accounts on. Even if someone can't get your password to other sites from inside your account, they could use that to log in to other websites if you don't have two-factor authentication on.

LastPass does have two-factor authentication, though, so that's something you will want to turn on if you want an extra layer of security on pretty much any account on any website that supports it.

As always, 2FA is worth setting up. Given that you need to sign off on access to your accounts via your phone, a bad actor getting your password doesn't mean they can actually get into your account. It's a nifty tool and only takes a few moments to get up and running.

Читайте на сайте


Smi24.net — ежеминутные новости с ежедневным архивом. Только у нас — все главные новости дня без политической цензуры. Абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Мы не навязываем Вам своё видение, мы даём Вам срез событий дня без цензуры и без купюр. Новости, какие они есть —онлайн с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии. Smi24.net — живые новости в живом эфире! Быстрый поиск от Smi24.net — это не только возможность первым узнать, но и преимущество сообщить срочные новости мгновенно на любом языке мира и быть услышанным тут же. В любую минуту Вы можете добавить свою новость - здесь.




Новости от наших партнёров в Вашем городе

Ria.city
Музыкальные новости
Новости России
Экология в России и мире
Спорт в России и мире
Moscow.media






Топ новостей на этот час

Rss.plus





СМИ24.net — правдивые новости, непрерывно 24/7 на русском языке с ежеминутным обновлением *