I just wanted to share a phishing email targeting Bitwarden users I’ve just got today - in case anyone would wonder if “We Have Been Hacked — Protect Your Bitwarden Vault with the New Desktop App” is real. The website seems to be already marked as phishing by CloudFlare, but I bet they will come back with some another one later.
I just got a message that was quite convincing, telling me about a possible compromised desktop app. I should immediately update my apps by going to https://bitwardendesktop…
As it is actually passing DKIM and looks quite real, I thought I post it here for other to be aware:
From: BITWARDEN <hello@bitwardennewschannel...>
To: (me, but not my bitwarden address)
Subject: We Have Been Hacked — Protect Your Bitwarden Vault with the New Desktop App
Dear Bitwarden Users,
We’re rolling out a new, strengthened Bitwarden Desktop App to address a recently discovered issue in older desktop builds. Our investigation confirmed that Bitwarden’s zero-knowledge, client-side encryption kept your vault contents protected; however, legacy clients introduced an elevated risk around local metadata and cache integrity.
Your quick 3-minute fix
Step 1: Download the latest Bitwarden Desktop App Here: https://bitwardendesktop..../
Step 2: Install, then sign in with your master password.
Step 3: Let your vault re-sync; then open Vault Health Report to verify everything looks good.
(Optional) Clear the old app cache after upgrading.
Why this matters
Older desktop versions relied on components that could be targeted for memory injection or local cache manipulation. The new release blocks these vectors with digitally signed installers, hardened sandboxing, integrity verification, and upgraded cryptographic defaults.
Extra precautions we recommend
Confirm 2FA is enabled and backed up.
Consider rotating your master password and reviewing emergency access settings.
Ensure your browser extension and mobile apps are on their latest versions.
If you think your account may have been impacted, please reach out through the support widget on our download page to connect directly with our Security Response Team.
For general questions or feedback, you can also start a conversation through the live chat available on that page.
Your continued trust and feedback inspire us to strengthen Bitwarden every day and deliver the most secure, reliable password management experience possible.
With care,
Bitwarden Customer Support & Security
This email has been confirmed not to come from Bitwarden.
Bitwarden only has email supports. There is NO support widget or live chat.
Also, the subject line “We Have Been Hacked” () is highly unlikely to be used in a real breach. The security companies usually notify their customers with much calmer (sometimes even deceptive) tone.
For transparency: I adjusted the title a bit. (fromAttention to phishing suggesting new desktop apptoAttention to phishing mail - maliciously suggesting a “new desktop app”)
“Big news” tends to be “bigly reported”. A legitimate “We Have Been Hacked” would hit the tech news; perhaps the mass media will report it, will somehow be mentioned on Bitwarden’s web site and undoubtedly would become the day’s topic on this community. If big news is not coming from many directions, it probably is not big news.
Bitwarden desktop has a “check for updates” menu item under the Help menu, as do browsers, OSes, and extension/app stores. This is the safe (and somewhat standardized) way to check for and to apply updates.