Is this email authentic: Action required to maintain your Bitwarden account

Adding to this:

E.g. the legitimate “New device Logged In…” mails in the EU region do get send from a bitwarden.eu mail address.

PS: As my account is in the EU region server as well, I didn’t get such an email.

… and the question remains, what could be meant at all. – Even it if it was KDF, I think not even on the .com servers the accounts with “Low KDF” warnings were “forcibly migrated” (hence, this still open feature request: Increasing the default number of PBKDF2 for existing accounts).

Regarding “data encryption” of the vault etc. - I think there are some changes going on in the background (e.g. Remove legacy encryption services by quexten · Pull Request #14551 · bitwarden/clients · GitHub ?!), but as written before, so far nothing was announced or mentioned anywhere AFAIK that would even involve any user action.

And as you @grb alluded to: the EU server region is quite “new” (I think it was introduced around mid 2023), so very unlikely that there suddenly is any pressing “encryption migration” needed for those “recent” accounts…

So in sum, the whole “issue” of the mail doesn’t seem very plausible / valid to me. :thinking: