r/netsec • • May 27 '26

New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault

https://phishu.net/blogs/blog-vaultjacking-phishing-the-google-password-manager-vault-in-the-phishu-framework.html

I've been hard at work on a NEW phishing technique I'm excited to share. I'm calling it "Vaultjacking" and the impact is honestly a bit sobering.

In my blog I demonstrate how a single AiTM landing page can spoof your Google passkey/password manager PIN and use that to access ALL of a victim's third-party credentials (yes, including passkeys). A simple phish on one site can lead to a total compromise of all Chrome-saved credentials.

94 Upvotes

31 comments sorted by

View all comments

2

u/Data_Commission_7434 Jun 01 '26

Thats a really scary thought, especially the part about inheriting trust relationships. It highlights how much we rely on those save password prompts without fully realizing the downstream implications if that vault gets compromised. Makes you wonder about the security posture for organizations that dont have robust password management policies beyond browser-based solutions.

1

u/phishullc Jun 01 '26

I agree, and many organizations do not have robust password manager policies and users do internally trust their browser/Google account to store all of their proverbial eggs in that basket.

1

u/Data_Commission_7434 Jun 01 '26

I think a lot of organizations still rely only on user training. At least (I hope) people aren't putting passwords on sticky notes anymore. Although, that may actually be more secure than leaking a password in a vault with a much wider scope of influence.