Hackers are targeting your password manager app

Cyberattacks on stored credentials are increasing, according to a new report.
By  on 
Login credentials
Password managers are increasingly under attack from cyber criminals. Credit: Nando Vidal via GETTY Images

Do you use 1Password, LastPass, NordPass, or any other password manager? You're not alone. According to a 2023 Security.org study, roughly one in three people use a password manager to secure their login information. Password managers make logging in to your apps, social media accounts, and other online services easy.

They're also increasingly being targeted by cybercriminals.

According to a new report from cybersecurity firm Picus Security, cyberattacks on password managers and similar services, such as browser-stored credentials, have tripled compared to the previous year. The firm detailed these findings in its Red Report 2025.

Researchers found that out of more than a million malware variants, 25 percent of all malware targeted password managers or other credential storage services.

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

"For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework," Picus Security said, referencing an industry framework for classifying cyberattacks.

According to Picus, cybercriminals are increasingly deploying multi-stage attacks, which the firm's researchers have dubbed "SneakThief." SneakThief describes a new type of malware attack that involves "increased stealth, persistence, and automation." These new malware attacks contain dozens of "malicious actions," which aid the hacker in gaining access and exporting data without getting caught.

With so many apps and online platforms to manage logins for, more internet users have adopted password storage utilities to help manage them all. But, in turn, hackers have adjusted their malicious campaigns to shift their focus towards password managers. And it makes sense. Why would a hacker put their time and effort into stealing a target's login credentials to just one service when they could steal all their login credentials? Why steal a key to open just one door when you can take the master key and access everything?

"Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom," said Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan. "It’s vital that password managers are used in tandem with multi-factor authentication and that employees never reuse a password, especially for their password manager."

Topics Cybersecurity


Recommended For You
'Football Manager 25' canceled not long before it was supposed to come out
Premier League soccer ball on grass


Hackers take over Google Chrome extensions in cyberattack
Google Chrome logo on laptop

U.S. Treasury confirms it was breached by China-backed hackers
 The sun flares over the headquarters of the U.S. Treasury

New 'browser syncjacking' cyberattack lets hackers take over your computer via Chrome
Google Chrome logo on laptop

Trending on Mashable
NYT Connections hints today: Clues, answers for March 7, 2025
A close-up of an NYT Connections game on a smartphone.

NYT Strands hints, answers for March 7
A game being played on a smartphone.

Wordle today: Answer, hints for March 7, 2025
A close-up of a Wordle game open on a smartphone.

Why are there no iPhones in 'Severance'?
By Jake Kleinman
John Turturro in "Severance."

Tesla sales are reportedly falling globally. How bad it is and where.
Tesla logo
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!