LastPass warns users about a fake copy of its app on Apple's App Store, with a similar name and logo, likely used as a phishing app to steal users' credentials
what you need to know Amrita Khalid / The Verge : Fake LastPass phishing app nabs a five-star rating on Apple's App Store.The slyly named “LassPass” … Heinrich Long / RestorePrivacy : Fake LastPass Password Manager App Appears on Apple's App Store Kate Irwin / PCMag : Beware: There's a Fake LastPass App on Apple's App Store Threads: Ian Betteridge / @ianbetteridge : Yeah, this is why Apple needs all that power - so they can protect us from scam apps... oh. Mastodon: Tuta / @Tutanota@mastodon.social : Good thing the #Apple App Store is secure, it would be a shame if the #DigitalMarketsAct allowed alternative platforms to set up shop and start pushing fake software to #iOS devices... Oh wait 👉 https://arstechnica.com/... [image] @hagen@mastodon.social : fake password manager in the app store. isn't this what the 30 % cut is supposed to protect us from? https://www.bleepingcomputer.com/ ... Zack Whittaker / @zackwhittaker@mastodon.social : New, by @Sarahp: A fake app that was masquerading as password manager LastPass on the App Store has been removed, whether by Apple or the fake app's developer is yet unclear — Apple has not commented. … Nick Heer / @nickheer@c.im : If alternate app stores are permitted on iOS, they will have different standards which might permit fraudulent apps, is what I have been told. https://blog.lastpass.com/... Mike Rockwell / @mike@libertynode.net : It's a good thing that Apple keeps our devices safe by reviewing everything before it's available in the App Store. https://blog.lastpass.com/... Bluesky: Emil Protalinski / @emilprotalinski.bsky.social : I don't understand. I thought Apple uses the money from its 30% tax to stop phishing apps from getting into its app store? [embedded post] Mary Branscombe / @marypcbuk.bsky.social : if Apple is going to insist that having the only app store on its devices is there to be a security barrier, letting through fake apps doesn't help with that argument [embedded post] X: @mysk_co : Ironically, Apple just added this new screen when you open the App Store for the first time on iOS 17.4 beta 2: (A safe and trusted place) 🤦♂️ [image] @dylanmcd8 : It's beyond time for a complete redo of App Review. Do the whole thing over. New policies. New training. New review methods. It's all so broken and inconsistent. I don't mind most of the rules Apple imposes, but they enforce them so inconsistently AND let stuff like this happen. Joe Rossignol / @rsgnl : Impeccable timing, Apple! [image] Marcin Krzyzanowski / @krzyzanowskim : who need sideloading to trick apple users if that is still possible all these years Florian Mueller / @florian4gamers : Apple argues the App Store is safer with a monopoly than if there is effective competition between multiple app stores. For years, such problems as the one described below have been highlighted. Let two or more app stores compete on security. @9to5mac : Update: LassPass is no more. Apple has pulled the reviewed and approved sus LastPass imposter from the App Store. https://9to5mac.com/... Patrick Wardle / @patrickwardle : Bypass Apple's App Store review by ....changing one letter!? 🤦🏻♂️ 😓 “The fake app uses a similar name to the genuine [LastPass] app, a similar icon, and a red-themed interface ...however, the fake app's name is ‘LassPass,’ instead of ‘LastPass’” https://www.bleepingcomputer.com/ ... @gcluley : A fake version of LastPass somehow made its way into Apple's app store... Come on @Apple, you shouldn't have let this through... https://blog.lastpass.com/... [image] @lastpass : ⚠️ Don't fall for fraudulent app impersonating LastPass in Apple's App Store. We are actively working to get this application taken down. Download our official app here: https://apps.apple.com/.... Learn more on our blog. https://blog.lastpass.com/... #FraudAlert [image] Forums: r/technology : A password manager LastPass calls “fraudulent” booted from App Store — “LassPass” mimicked the name and logo of real LastPass password manager r/apple : Fake LastPass password manager spotted on Apple's App Store Ars OpenForum : A password manager LastPass calls “fraudulent” booted from App Store MacRumors Forums : Fake LastPass App Sneaks Past Apple's Review Team
Context & Ripple Effects
The impersonation is another failure mode for App Store screening: related coverage has documented lookalike apps aided by weak enforcement and fake reviews and an unrelated ChatGPT-branded app that reached the store’s paid rankings.
It matters especially for a password manager, where a convincing listing can turn the distribution layer into a credential-harvesting entry point. The app’s removal limits further exposure, but does not establish how many users installed it or submitted information.
First-order effects
- LastPass must direct customers to its legitimate listing and assess whether users who installed the impersonator need to change credentials or take other protective steps.
- Apple has removed the fraudulent listing after its review process admitted it; the immediate gap is preventing similarly named, visually similar submissions from reaching search and download pages.
Second-order effects
- Password-manager vendors and other high-value app brands face stronger incentives to monitor storefront listings and warn users, shifting some anti-impersonation work from platform review teams to brands.
- The incident adds evidence to a pattern in which an unaffiliated ChatGPT-branded subscription app and other deceptive listings passed storefront controls, increasing pressure for Apple to improve review, identity checks, and reporting response times.
Third-order effects
- If high-trust utility apps can be convincingly mimicked within curated stores, platform safety claims will increasingly be judged by enforcement outcomes rather than by the existence of centralized review.
- The case reinforces distribution-layer liability as a durable platform issue: stores that control discovery and approval may face growing expectations to detect brand impersonation before users are exposed.
The trend: Curated app stores are confronting a persistent trust problem in which impersonation scams exploit recognizable brands faster than centralized review can reliably identify them.