No legitimate password manager will ever ask you for your master password. Not in an email, not in a support chat, not behind a link in a security notice. If something is asking, it isn’t your password manager. Password manager phishing depends entirely on you not knowing that.
That single rule catches nearly every attack of this kind. Still, it’s worth knowing what the rest of the con looks like, because these campaigns have become specific, well-produced, and aimed squarely at people who already take security seriously.
What password manager phishing actually looks like
The construction is consistent enough to describe in advance.
The attacker registers a domain that contains a brand name without being that brand’s domain – something on the pattern of example-alerts.com or example-compliance.com. These cost a few dollars and anyone can buy one. Mail then goes out from an address on that domain, which is why it survives a glance and often survives basic filtering too.
The wrapper is administrative. A policy update to acknowledge, a compliance notice, a document waiting for your signature. Clicking through leads to a page asking you to sign in, and sometimes to a download.
In every case, the target is the master password.
What’s usually absent is everything people were taught to watch for. There’s no broken English, no improbable refund, no threat that your account closes within the hour. It’s built to look like routine admin – the sort of message you skim on a Tuesday morning and action without really reading. The Anti-Phishing Working Group has logged over a million phishing attacks in a single quarter, and the ones that succeed are rarely the dramatic ones.
That’s the shift worth internalizing. The obvious tells are the tells of a decade ago.
Four things that give it away
The domain is close, but not exact. By contrast, real notices come from the company’s actual domain. example-alerts.com is a different website that anyone can register, and the brand name sitting inside it means nothing at all. Before you trust a page, read the domain from the right – the part immediately before the first single slash is who you’re actually talking to. Everything to the left of it is decoration the sender controls.
It arrives as a document to review. Policy updates, compliance notices, and shared documents are the current favorite wrapper, because they carry built-in authority and a reason to click without sounding alarming.
It asks you to act inside the email. This is the load-bearing tell. A real security alert tells you something happened; it doesn’t hand you the door to walk through. As the FTC puts it, legitimate companies don’t email or text you a link to update your details.
Your password manager stays quiet. Autofill matches saved logins against the site you’re actually on. On a lookalike domain, the entry doesn’t match, so nothing is offered. If you’re staring at a familiar login page and your manager isn’t filling it, treat that silence as information rather than a glitch to work around by copying and pasting.
Why the master password is the prize
mSecure uses end-to-end AES-256 encryption and a zero-knowledge architecture – only you can access your data, not even mSeven Software can. That’s the correct design, and it has a consequence worth being clear-eyed about: your master password is the only key that exists. There’s no support ticket that recovers it and no administrator who can reset it for you.
As a result, it’s the single most valuable credential you own. One master password is every account inside the vault in one step.
It also means nobody here can ever legitimately ask you for it. We couldn’t use it if you sent it to us, and we’d have no reason to want it.
What a real security alert never does
- Ask for your master password, in any form or for any reason
- Send you a link to sign in or confirm credentials
- Require a download to read the message
- Attach a deadline to a security instruction
If a notice makes you uneasy, close it and go to the service yourself – type the address, or open the app you already have installed. Navigating there under your own steam removes the attacker from the process entirely. It costs about fifteen seconds.
If you already clicked
Clicking a link isn’t the same as being compromised, and the response is straightforward.
- Change your master password now, from inside the app – never from a link in the email that worried you.
- Run a scan with your security software, particularly if you downloaded anything.
- Check your exposure. mSecure’s Security Center flags weak and reused passwords in your vault, but it doesn’t monitor breaches. For that, Have I Been Pwned will tell you which breaches your email has appeared in.
- Report it. Send the email to your provider’s abuse address, forward phishing emails to reportphishing@apwg.org, forward suspect texts to 7726, and file at ReportFraud.ftc.gov.
- Review your vault for entries you don’t recognize, and change anything you reused elsewhere.
The defenses that hold up
Passkeys. A passkey is bound to the real site’s identity, so it simply won’t work on a lookalike domain – the phishing page can ask, and there’s nothing to hand over. mSecure stores and fills passkeys alongside your passwords; we covered how they work with built-in 2FA in Passkeys and OTPs. Where a service offers one, take it.
Unique passwords everywhere. Reuse is what turns one successful phish into six compromised accounts, and it remains the most common mistake people make. A generated password per site contains the damage to one site.
Two-factor on the vault itself. It’s the layer that still stands if the master password does get away from you.
None of this requires you to be suspicious of everything. Instead, it requires one habit: when a message wants you to sign in, don’t use its door. Use your own.
