/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

LastPass warns users about a fake copy of its app on Apple's App Store, with a similar name and logo, likely used as a phishing app to steal users' credentials

BleepingComputer Bill Toulas

Context & Ripple Effects

The fake listing arrives after a series of LastPass security incidents, including the theft of source code and technical information in 2022 and a later disclosure that attackers obtained backup copies of vault data. That history makes brand impersonation especially consequential: users already have reason to scrutinize any LastPass prompt for credentials.

The immediate issue is not a newly reported compromise of LastPass itself, but a counterfeit app using the company’s name and visual identity inside Apple’s storefront. It tests whether platform review and recognizable branding are sufficient safeguards for a security product’s users.

First-order effects

  • LastPass users who install the fake app risk submitting credentials to a phishing operation; LastPass must direct users to its legitimate listing and handle support fallout.
  • Apple must remove the reported impostor and review how a similarly named, similarly branded credential-targeting app passed through its App Store controls.

Second-order effects

  • The incident raises the support and trust burden for password-manager providers: users may become less willing to rely on store search alone when installing security software.
  • App-store review teams face greater pressure to detect impersonation of high-value brands, particularly where a fraudulent app can harvest credentials rather than merely mimic a product.

Third-order effects

  • If such listings recur, mobile distribution may shift toward stronger developer-identity verification and more prominent signals that distinguish official security apps from clones.
  • The episode underscores a structural weakness in centralized app marketplaces: approval can reduce risk, but it cannot eliminate brand-impersonation attacks aimed at credentials.

The trend: Credential phishing is increasingly exploiting trusted mobile distribution channels and familiar security brands, pushing app stores toward more rigorous anti-impersonation controls.

Discussion

  • @ianbetteridge Ian Betteridge on threads
    Yeah, this is why Apple needs all that power - so they can protect us from scam apps... oh.
  • @Tutanota@mastodon.social Tuta on mastodon
    Good thing the #Apple App Store is secure, it would be a shame if the #DigitalMarketsAct allowed alternative platforms to set up shop and start pushing fake software to #iOS devices...  Oh wait 👉 https://arstechnica.com/...  [image]
  • @zackwhittaker@mastodon.social Zack Whittaker on mastodon
    New, by @Sarahp: A fake app that was masquerading as password manager LastPass on the App Store has been removed, whether by Apple or the fake app's developer is yet unclear — Apple has not commented. …
  • @florian4gamers Florian Mueller on x
    Apple argues the App Store is safer with a monopoly than if there is effective competition between multiple app stores. For years, such problems as the one described below have been highlighted. Let two or more app stores compete on security.
  • @9to5mac @9to5mac on x
    Update: LassPass is no more. Apple has pulled the reviewed and approved sus LastPass imposter from the App Store. https://9to5mac.com/...
  • @mysk_co @mysk_co on x
    Ironically, Apple just added this new screen when you open the App Store for the first time on iOS 17.4 beta 2: (A safe and trusted place) 🤦‍♂️ [image]
  • @dylanmcd8 @dylanmcd8 on x
    It's beyond time for a complete redo of App Review. Do the whole thing over. New policies. New training. New review methods. It's all so broken and inconsistent. I don't mind most of the rules Apple imposes, but they enforce them so inconsistently AND let stuff like this happen.
  • @rsgnl Joe Rossignol on x
    Impeccable timing, Apple! [image]
  • @patrickwardle Patrick Wardle on x
    Bypass Apple's App Store review by ....changing one letter!? 🤦🏻‍♂️ 😓 “The fake app uses a similar name to the genuine [LastPass] app, a similar icon, and a red-themed interface ...however, the fake app's name is ‘LassPass,’ instead of ‘LastPass’” https://www.bleepingcomputer.com/…
  • @krzyzanowskim Marcin Krzyzanowski on x
    who need sideloading to trick apple users if that is still possible all these years
  • @gcluley @gcluley on x
    A fake version of LastPass somehow made its way into Apple's app store... Come on @Apple, you shouldn't have let this through... https://blog.lastpass.com/... [image]
  • @lastpass @lastpass on x
    ⚠️ Don't fall for fraudulent app impersonating LastPass in Apple's App Store. We are actively working to get this application taken down. Download our official app here: https://apps.apple.com/.... Learn more on our blog. https://blog.lastpass.com/... #FraudAlert [image]
  • r/technology r on reddit
    A password manager LastPass calls “fraudulent” booted from App Store — “LassPass” mimicked the name and logo of real LastPass password manager