Hello, @martin.speeks
We can confirm this email was not sent by LastPass and should be quarantined.
All LastPass' official domains and IP ranges can be found within this allowlisting and firewall support article.
TL/DR: These are currently the domains we utilize:
.com
.lastpass.com
no-reply@drata.com
More information can be found in our latest blog post here: https://blog.lastpass.com/posts/july-2026-phishing-campaign-compliance
There’s a close link between social engineering and cybersecurity. By better understanding how social engineering is performed, you can protect yourself from these attacks.
Be suspicious of unsolicited messages
Be suspicious when you receive a message that you were not expecting. At first look, the message might look legitimate.
Never use the contact information in a suspicious message
If you received a suspicious message, contact the presumed sender using information you’ve looked up independently (that is, don’t use any contact information in the message you received) to make sure it was actually them who sent the message.
Don’t assume your favorite apps are safe
Since hackers are aware that people are more vigilant about phishing emails, they’re increasingly trying to reach you through the apps and sites you trust, like music stores or social media.
Don’t assume your business communications are safe
If you receive an email from a coworker that looks suspicious, reach out to that coworker using another method of communication, like a phone call, and make sure it was really that colleague who sent you the message.
Think twice before sharing personal information online
Cybercriminals can analyze your comments on Facebook memes which they can then use to steal your identity or break into one of your accounts. They can also extract personal information from your public social media posts to gain your trust in a future phishing attack.
Use multi-factor authentication (MFA)
MFA gives you an added layer of protection against social engineering attacks. Even if a hacker already has your password, they won’t be able to gain control of your account unless they are also able to provide another form of authentication that you’ve already set up, like a passcode from an authenticator app. Make this even harder by breaking the cycle of password reuse and maintaining strong passwords on all your accounts.