Description

VaultJacking is a newly discovered phishing technique that exposes a major weakness in cloud-synced password management systems. The attack specifically targets Google Password Manager and demonstrates how cybercriminals can steal an entire vault of saved passwords and passkeys using only a single captured 6-digit PIN. Unlike many cyber threats that rely on malware or device compromise, VaultJacking works entirely through deception and social engineering, making it especially dangerous for everyday users and organizations alike.The attack begins with a fake Google Password Manager sign-in page that closely resembles the legitimate interface. When a victim enters their Google Password Manager PIN, the attacker can use that information to unlock the victim’s synchronized credential vault. This includes passwords, passkeys, and other authentication data stored across devices connected to the same Google account. Researchers from Phishu demonstrated that the technique abuses Google’s synchronization architecture and Security Token Service. Once the correct PIN is obtained, attackers can register their own device within the victim’s sync environment and download the encrypted vault contents. Even strong security protections like hardware-backed passkeys may still be compromised because the synchronization process transfers the key information required for authentication.One of the most alarming aspects of VaultJacking is that it does not require malware installation, prior access to the victim’s device, or continuous session hijacking. A single phishing event is enough to compromise the entire credential ecosystem associated with the account. Cybersecurity experts recommend separating personal and work accounts, avoiding storage of sensitive credentials in shared browser profiles, and using dedicated password managers that do not rely on cloud synchronization. User awareness is also critical. Notifications about new sign-ins, added passkeys, or device registrations should always be treated as potential security warnings requiring immediate verification.