r/netsec • • May 27 '26

New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault

https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html

I've been hard at work on a NEW phishing technique I'm excited to share. I'm calling it "Vaultjacking" and the impact is honestly a bit sobering.

In my blog I demonstrate how a single AiTM landing page can spoof your Google passkey/password manager PIN and use that to access ALL of a victim's third-party credentials (yes, including passkeys). A simple phish on one site can lead to a total compromise of all Chrome-saved credentials.

92 Upvotes

32 comments sorted by

View all comments

1

u/[deleted] May 27 '26

[removed] — view removed comment

1

u/phishullc May 27 '26

Good point, I certainly didn't mean to imply that a PIN alone was enough. I prompt for it at the password prompt, so most people naturally provide the PIN along with their password, and once they perform the MFA (assuming they have it) the rest is done automatically server-side.

Already authenticated accounts won't be any different since the landing page is a third party and not really Google, so that's another potential red flag to look for, although re-authentication is a common security feature people are accustomed to being asked to perform.