LastPass is warning that attackers are impersonating it and Bitwarden with fake security alerts to lure password-manager users to phishing sites. The emails, sent from look-alike domains rather than the real services, mimic corporate notices about updated security policies and push recipients to a page impersonating DocuSign. LastPass stresses its systems were not breached and the messages did not come from its infrastructure. Password managers are attractive phishing targets because compromising one can unlock every stored credential, and users often trust vendor-branded alerts. Related campaigns have pushed fake more-secure desktop apps that actually install remote-access tools, and similar lures have impersonated other password managers.