LastPass warns users about a fake copy of its app on Apple's App Store, with a similar name and logo, likely used as a phishing app to steal users' credentials
BleepingComputerBill Toulas
Context & Ripple Effects
The fake listing arrives after a series of LastPass security incidents, including the theft of source code and technical information in 2022 and a later disclosure that attackers obtained backup copies of vault data. That history makes brand impersonation especially consequential: users already have reason to scrutinize any LastPass prompt for credentials.
The immediate issue is not a newly reported compromise of LastPass itself, but a counterfeit app using the company’s name and visual identity inside Apple’s storefront. It tests whether platform review and recognizable branding are sufficient safeguards for a security product’s users.
First-order effects
LastPass users who install the fake app risk submitting credentials to a phishing operation; LastPass must direct users to its legitimate listing and handle support fallout.
Apple must remove the reported impostor and review how a similarly named, similarly branded credential-targeting app passed through its App Store controls.
Second-order effects
The incident raises the support and trust burden for password-manager providers: users may become less willing to rely on store search alone when installing security software.
App-store review teams face greater pressure to detect impersonation of high-value brands, particularly where a fraudulent app can harvest credentials rather than merely mimic a product.
Third-order effects
If such listings recur, mobile distribution may shift toward stronger developer-identity verification and more prominent signals that distinguish official security apps from clones.
The episode underscores a structural weakness in centralized app marketplaces: approval can reduce risk, but it cannot eliminate brand-impersonation attacks aimed at credentials.
The trend: Credential phishing is increasingly exploiting trusted mobile distribution channels and familiar security brands, pushing app stores toward more rigorous anti-impersonation controls.
Good thing the #Apple App Store is secure, it would be a shame if the #DigitalMarketsAct allowed alternative platforms to set up shop and start pushing fake software to #iOS devices... Oh wait 👉 https://arstechnica.com/... [image]
New, by @Sarahp: A fake app that was masquerading as password manager LastPass on the App Store has been removed, whether by Apple or the fake app's developer is yet unclear — Apple has not commented. …
Apple argues the App Store is safer with a monopoly than if there is effective competition between multiple app stores. For years, such problems as the one described below have been highlighted. Let two or more app stores compete on security.
Ironically, Apple just added this new screen when you open the App Store for the first time on iOS 17.4 beta 2: (A safe and trusted place) 🤦♂️ [image]
It's beyond time for a complete redo of App Review. Do the whole thing over. New policies. New training. New review methods. It's all so broken and inconsistent. I don't mind most of the rules Apple imposes, but they enforce them so inconsistently AND let stuff like this happen.
Bypass Apple's App Store review by ....changing one letter!? 🤦🏻♂️ 😓 “The fake app uses a similar name to the genuine [LastPass] app, a similar icon, and a red-themed interface ...however, the fake app's name is ‘LassPass,’ instead of ‘LastPass’” https://www.bleepingcomputer.com/…
A fake version of LastPass somehow made its way into Apple's app store... Come on @Apple, you shouldn't have let this through... https://blog.lastpass.com/... [image]
⚠️ Don't fall for fraudulent app impersonating LastPass in Apple's App Store. We are actively working to get this application taken down. Download our official app here: https://apps.apple.com/.... Learn more on our blog. https://blog.lastpass.com/... #FraudAlert [image]