Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Meta AI Model Exploited to Hack Third-Party System
August 6, 2026
Cisco Patches Critical IOS XE Software Vulnerabilities
August 6, 2026
Malicious macOS ClickFix Domains Hide Atomic Stealer Attacks via Browser Fingerprinting
August 6, 2026
Home/Threats/VaultJacking Attack Steals Google Password Manager Vault via Captured PIN
Threats

VaultJacking Attack Steals Google Password Manager Vault via Captured PIN

Key Takeaways A novel phishing technique, dubbed “VaultJacking,” can compromise an entire Google Password Manager (GPM) vault. The attack exploits Google’s cross-device...

David kimber
David kimber
May 28, 2026 3 Min Read
61 0

Key Takeaways

  • A novel phishing technique, dubbed “VaultJacking,” can compromise an entire Google Password Manager (GPM) vault.
  • The attack exploits Google’s cross-device synchronization mechanism by tricking users into revealing their GPM PIN.
  • Once the 6-digit PIN is captured, attackers can access all stored passwords and passkeys, including hardware-backed ones, without needing prior device access or malware.
  • This is not a theoretical vulnerability but a demonstrated end-to-end attack, prompting security researchers to recommend specific mitigation strategies.

VaultJacking: A New Phishing Threat to Google Password Manager

A sophisticated new phishing method, termed “VaultJacking,” has emerged, posing a significant threat to users of Google Password Manager (GPM). This technique allows attackers to exfiltrate an entire vault of stored credentials, including all passwords and passkeys, by capturing a single 6-digit GPM PIN from a targeted user. This isn’t a speculative vulnerability; it’s a fully demonstrated attack that leverages inherent behaviors in how Google synchronizes credentials across multiple devices.

Table Of Content

  • Key Takeaways
  • VaultJacking: A New Phishing Threat to Google Password Manager
  • How the VaultJacking Attack Unfolds
  • What You Should Do

The core of the VaultJacking attack targets Google’s trusted cross-device passkey and password synchronization feature. By luring a victim to an authentic-looking but malicious sign-in page, attackers can prompt them to enter their GPM PIN. This seemingly innocuous action grants the attacker the “master key” to the victim’s entire synced credential vault. Consequently, every third-party login, every stored passkey, and all saved credentials immediately become accessible to the attacker.

How the VaultJacking Attack Unfolds

Researchers at Phishu were instrumental in identifying and thoroughly documenting the VaultJacking technique, integrating it into their PhishU adversary simulation framework. In a report shared with Cyber Security News (CSN), Phishu highlighted that this attack underscores the substantial risk introduced by synced credential vaults when their unlock mechanism is compromised through a single, well-orchestrated phishing event. The attack specifically exploits Google’s Security Token Service and its reliance on a Security Level Secret to facilitate cross-device synchronization.

Upon a victim entering their legitimate GPM PIN on a fraudulent phishing page, the PIN effectively unlocks the Security Level Secret on the attacker’s infrastructure. This action decrypts the synchronized vault, leading to the direct exfiltration of all stored credentials to the attacker. Crucially, this attack requires no prior compromise of the victim’s device and no malicious software needs to be installed, making it particularly insidious.

What sets VaultJacking apart is its ability to bypass Google’s “Live Device Found Session Credentials” defense. The attacker’s synchronization component utilizes the stolen PIN and an attacker-controlled passkey to authenticate from their own infrastructure. This authentication can occur long after any original session cookies have expired. The outcome is severe: a single captured PIN, without any prior installation, leads to the complete compromise of the user’s entire GPM vault. This includes hardware-backed passkeys, as Chrome versions 359 and later write their private-key bytes to the local Passkeys SQLite database, which are then carried within the sync payload. The researchers noted that no rate limiting or re-entry prompts impede the attacker once the PIN is successfully captured.

What You Should Do

Security professionals and users should approach VaultJacking as an inherent design trade-off rather than an unpatched software bug awaiting a vendor fix. Phishu has outlined several pragmatic steps organizations and individuals can implement to mitigate their exposure:

  • Segregate Work and Personal Credentials: Avoid storing personal site credentials within a work Chrome profile. A successful phishing attack targeting work credentials could inadvertently expose your personal vault, as attackers do not differentiate between the two.
  • Utilize Dedicated Profiles: Employ a separate, dedicated Chrome profile exclusively for personal site credentials and passkeys to maintain strict separation.
  • Consider On-Premises Password Managers: For environments that do not rely on Google Sync, deploying on-premises password managers can provide an unaffected alternative to GPM.
  • Heighten Awareness of Notifications: Educate users to treat notifications such as “new passkey added” or “new sign-in on Windows” as critical authentication events requiring immediate verification. These are often the only visible indicators of a VaultJacking attack in progress.

Organizations that have adopted passkeys without simultaneously implementing robust, authentication-resistant monitoring and security-domain governance are already operating with this threat model in mind. The appropriate response is not to abandon passkeys, but rather to implement stricter tiering and actively monitor the sync-layer architecture. The primary attack surface resides within policy and monitoring layers, which is where defensive efforts should be concentrated.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecurityExploitMalwarePatchphishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical Gogs Vulnerability CVE-2024-XXXXX Allows Remote Code Execution

Next Post

AI-Generated npm Malware Exposes Threat Actor’s GitHub Token

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical npm Supply Chain Attack Compromises Keyv Library, Hundreds of Packages
August 6, 2026
Attackers Exploit Microsoft, Zoom Flaws to Target Government Agencies
August 6, 2026
Google Blogger Bug Locked Legitimate Sites, Mistaking Them for Malware
August 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us