LastPass Last Phish?

If you believe that phishing scams had diminished or subsided, this week’s cybersecurity landscape was characterized by the active exploitation of critical vulnerabilities and, notably, phishing scams. A sophisticated phishing scam targeted LastPass users by sending them fraudulent “death claims” emails, with the intention of obtaining Master Passwords. This financially motivated campaign was associated with the CryptoChameleon group, underscoring the persistent threat posed by social engineering alongside nation-state activities that exploit flaws in Windows and target critical infrastructure.

for the week October 26, 2025, 96th edition

☝️ TWA

Phishing is a fraudulent activity where individuals attempt to deceive others into revealing sensitive information, such as passwords, by posing as trustworthy entities. In this case, the phishing campaign targets LastPass users by sending fabricated death claims. The objective of this scam is to trick users into disclosing their master passwords, thereby compromising their account security.

🤷‍♀️ What now?: Advice for LastPass Users (and everyone else):

• Never enter your Master Password on a link received via email or text message.

• Only log in to your password manager through the official application or a saved bookmark.

• Be wary of messages demanding immediate action.

Tools: Self. You are the best security system.

[This is an advertisement.

This is an advertisement.

This is an advertisement.

about this edition and Inside Hexagon

This week, we have compiled a limited number of stories, adhering to our weekly tradition of sharing only ten. Phishing scams have regained prominence in the news this week, highlighting the importance of maintaining vigilance in safeguarding our cybersecurity practices.

Happy Halloween!

As we conclude Cybersecurity Awareness Month, we extend a warm invitation to all. Hexagon Center stands ready to assist you in safeguarding your cyber life and technology. Volunteering with us is an integral part of our mission to ensure your safety. We encourage you to join us or spread the word about our services.

This is an advertisement.

HOUSEKEEPING

Glossary/Legend:

  • Personal Identifier - A unique word or phrase shared exclusively with an individual or a group, serving as a means of identification and affirmation within the established relationship. It is recommended that 2 or more Personal Identifiers be established per person.

  • MFA (Multi-factor authentication or 2FA or 2-Factor Authentication) - a multi-step or 2-step account login process that requires users to enter more information than just one.

  • Cyber hygiene - the regular practices and procedures individuals and organizations use to maintain the health and security of their devices, networks, and data.

  • Cyberattack - A malicious attempt to gain unauthorized access to a computer system, network, or device. The goal of a cyberattack is to disrupt or damage the target, or to steal data, intellectual property, or money.

  • Malware (short for malicious software) - refers to any intrusive software developed by cybercriminals (often called hackers) to steal data and damage or destroy computers and computer systems.

  • Ransomware - A type of malware that locks or encrypts a victim's files and demands a ransom payment to unlock and decrypt them. Ransomware can infect a variety of devices, including computers, smartphones, printers, and more.

Spread cybersecurity culture

Do you have any suggestions on how we can further share this newsletter? Tell your friends and family about us by sharing with them the Hexagon Center official website:
View archives at hxweekly.beehiiv.com

Even though we aim to provide you the most current and critical information to keep you safe, threat actors work 24/7 and this newsletter publishes only once a week. Even though we are available via a hotline, it is crucial that you stay up to date via other sources as well to be informed on how you may be at risk.

You may reply to this newsletter or email us at
[email protected]

Send us any questions or things you want to talk about. Please share some fun facts with us. We welcome feedback and suggestions.

Hexagon Center is formed as a nonprofit corporation in California for public benefit,
and is tax-exempt under section 501(c)(3) of the Internal Revenue Code.

DISCLAIMER

Cybersecurity is an ever-changing field, and threats may evolve. While Hexagon Center strives to provide accurate and timely information, we cannot guarantee absolute security. Users are responsible for implementing their security measures and staying informed about the latest cybersecurity developments. Hexagon Center is not responsible for any cyber or scam attacks by our readers. HX Weekly tips are advice are not official positions of Hexagon Center nor is Hexagon Center responsible for its content.

Content of this newsletter is not an official representation of Hexagon Center.

Reply

or to participate.