{"id":8760,"date":"2025-11-15T16:04:13","date_gmt":"2025-11-15T16:04:13","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=8760"},"modified":"2025-11-15T16:04:13","modified_gmt":"2025-11-15T16:04:13","slug":"can-password-managers-get-hacked-right-heres-what-to-know","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=8760","title":{"rendered":"Can password managers get hacked? Right here\u2019s what to know"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"sub-title\">Look no additional to learn the way cybercriminals might attempt to crack your vault and how one can hold your logins secure<\/p>\n<div class=\"article-authors d-flex flex-wrap\">\n<div class=\"article-author d-flex\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/our-experts\/phil-muncaster\/\" title=\"Phil Muncaster\"><picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2021\/04\/Phil_Muncaster.jpg\" media=\"(max-width: 768px)\"\/><img decoding=\"async\" class=\"author-image me-3\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x45\/wls\/2021\/04\/Phil_Muncaster.jpg\" alt=\"Phil Muncaster\"\/><\/picture><\/a><\/div>\n<\/div>\n<p class=\"article-info mb-5\">\n        <span>13 Nov 2025<\/span><br \/>\n        <span class=\"d-none d-lg-inline\">\u00a0\u2022\u00a0<\/span><br \/>\n        <span class=\"d-inline d-lg-none\">, <\/span><br \/>\n        <span>5 min. learn<\/span>\n    <\/p>\n<div class=\"hero-image-container\">\n        <picture><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x266\/wls\/2025\/11-25\/password-managers-cybersecurity-risks.png\" media=\"(max-width: 768px)\"\/><source srcset=\"https:\/\/web-assets.esetstatic.com\/tn\/-x425\/wls\/2025\/11-25\/password-managers-cybersecurity-risks.png\" media=\"(max-width: 1120px)\"\/><img decoding=\"async\" class=\"hero-image\" src=\"https:\/\/web-assets.esetstatic.com\/tn\/-x700\/wls\/2025\/11-25\/password-managers-cybersecurity-risks.png\" alt=\"How password managers can be hacked \u2013 and how to stay safe\"\/><\/picture>    <\/div>\n<\/div>\n<div>\n<p>The common web person has an estimated 168 passwords for his or her private accounts, in line with a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/uk.finance.yahoo.com\/news\/people-around-170-passwords-average-121100310.html\" target=\"_blank\" rel=\"noopener\">research from 2024<\/a>. That\u2019s an enormous 68% improve on the tally 4 years beforehand. Given the safety dangers related to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2020\/05\/28\/people-know-reusing-passwords-risky-most-do-it-anyway\/\" target=\"_blank\" rel=\"noopener\">sharing credentials throughout accounts<\/a>, and of utilizing <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2020\/05\/07\/5-common-password-mistakes-you-should-avoid\/\" target=\"_blank\" rel=\"noopener\">simple-to-guess passwords<\/a>, most of us need assistance managing these logins. That is <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/2023\/04\/11\/10-things-look-buying-password-manager\/\" target=\"_blank\" rel=\"noopener\">the place password managers are available<\/a>: enabling us to retailer and recall lengthy, sturdy and distinctive passwords for every of our on-line accounts.<\/p>\n<p>Nonetheless, this doesn\u2019t imply that these password vaults are a silver bullet or that it is best to decrease your vigilance on-line. Provided that they actually maintain the keys to our digital lives, they\u2019ve additionally change into a well-liked goal for cybercriminals. Listed here are six potential dangers and a few concepts on how you can mitigate them.<\/p>\n<h2>6 password supervisor safety issues<\/h2>\n<p>With entry to the credentials saved in your password supervisor, risk actors might hijack your accounts to commit id fraud, or promote entry\/passwords to others. That\u2019s why they\u2019re at all times in search of new methods to focus on you. Look out for the under:<\/p>\n<h3>1. Compromise of your grasp password<\/h3>\n<p>The great thing about password managers is that with a single, memorable password, you&#8217;ll be able to entry the vault that shops all your on-line credentials. Nonetheless, the issue with this strategy is that, if cybercriminals can <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/lastpass-users-warned-their-master-passwords-are-compromised\/\" target=\"_blank\" rel=\"noopener\">pay money for that grasp password<\/a>, they acquire the identical degree of entry. This might occur through a \u201cbrute-force\u201d assault, the place they basically use automated instruments to attempt completely different passwords repeatedly till they lastly stumble on the appropriate one. An alternative choice is by exploiting vulnerabilities within the password supervisor software program, or tricking customers with phishing pages, as detailed under.<\/p>\n<h3>2. Phishing\/rip-off advertisements<\/h3>\n<p>Risk actors have been identified to submit <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.ghacks.net\/2023\/01\/31\/the-hidden-threat-1password-password-manager-phishing-ads-on-google\/\" target=\"_blank\" rel=\"noopener\">malicious advertisements<\/a> to Google Search designed to lure victims to faux websites which harvest their e mail handle, grasp password and secret key (if relevant). The hazard with these advertisements is that they appear respectable and should seem within the search rankings if you Google your password supervisor. The phishing pages they\u2019re linked to are spoofed to seem as if they&#8217;re the true deal. For instance a website could also be <span style=\"font-family: courier new, courier, monospace;\">\u201cthe1password[.]com\u201d<\/span> or <span style=\"font-family: courier new, courier, monospace;\">\u201capp1password[.]com,\u201d<\/span> as a substitute of the unique \u201c1password.com.\u201d Or <span style=\"font-family: courier new, courier, monospace;\">\u201cappbitwarden[.]com\u201d<\/span> as a substitute of \u201cbitwarden.com.\u201d Should you click on by to such a web page, you\u2019ll be taken to a legitimate-looking login web page designed to steal your all-important password supervisor logins.<\/p>\n<h3>3. Password-stealing malware<\/h3>\n<p>Cybercriminals are nothing if not resourceful. Such are the riches on supply that some have gone to the difficulty of creating malware to steal credentials from victims\u2019 password managers. ESET researchers lately <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/deceptivedevelopment-targets-freelance-developers\/\" target=\"_blank\" rel=\"noopener\">noticed one such try<\/a> by a North Korean state-sponsored marketing campaign dubbed \u201cDeceptiveDevelopment.\u201d It discovered that \u201cInvisibleFerret\u201d malware which featured a backdoor command able to exfiltrating information from each <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/cybersecurity\/hidden-risks-browser-extensions\/\" target=\"_blank\" rel=\"noopener\">browser extensions<\/a> and password managers through Telegram and FTP. Among the many password managers focused have been 1Password and Dashlane.<\/p>\n<p>On this specific case, the malware was hidden in information downloaded by the sufferer as a part of an elaborate <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/business-security\/recruitment-spot-spy-job-seeker\/\" target=\"_blank\" rel=\"noopener\">faux job interview course of<\/a>. However there\u2019s no cause why malicious code with comparable properties couldn\u2019t be unfold in different methods, corresponding to through e mail, textual content or social media.<\/p>\n<h3>4. A password supervisor vendor breach<\/h3>\n<p>Password supervisor distributors know they&#8217;re a serious goal for risk actors. That\u2019s why they spend important time and sources making their IT environments as safe as potential. However they solely must make one mistake to probably let the dangerous guys in. In 2022, this worst-case state of affairs <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.cybersecuritydive.com\/news\/lastpass-cyberattack-timeline\/643958\/\" target=\"_blank\" rel=\"noopener\">occurred to LastPass<\/a>. Digital thieves compromised a LastPass engineer\u2019s laptop computer to entry the agency\u2019s improvement atmosphere. There they stole supply code and technical paperwork containing credentials, which enabled them to entry buyer information backups.<\/p>\n<p>This included clients\u2019 private and account data, which may very well be used for follow-on phishing assaults. A listing of all web site URLs of their vaults. And usernames and passwords for all clients. Though these have been encrypted, the hacker was capable of \u201cbrute pressure\u201d them (as mentioned above). That is thought to have led to an enormous <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/03\/feds-link-150m-cyberheist-to-2022-lastpass-hacks\/\" target=\"_blank\" rel=\"noopener\">US$150 million crypto-heist<\/a> and is a cautionary story that even the best-protected distributors might generally get breached.<\/p>\n<h3>5. Pretend password supervisor apps<\/h3>\n<p>Typically, cybercriminals play on the recognition of password managers in an try to reap passwords and unfold malware through faux apps. Even Apple\u2019s usually safe App Retailer <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/mashable.com\/article\/apple-app-store-approves-fake-lastpass-password-manager-app\" target=\"_blank\" rel=\"noopener\">allowed certainly one of these<\/a> malicious password supervisor apps to be downloaded by customers final 12 months. These threats are usually designed to steal that all-important grasp password, or else obtain information-stealing malware to the person\u2019s gadget.<\/p>\n<h3>6. Vulnerability exploitation<\/h3>\n<p>Password managers are in the end simply software program. And software program, being written (principally) by people, inevitably comprises vulnerabilities. If a cybercriminal manages to seek out and exploit certainly one of these bugs, they can elevate credentials out of your password vault. Alternatively, they might goal vulnerabilities in password supervisor plugins for net browsers to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/thehackernews.com\/2025\/08\/dom-based-extension-clickjacking.html\" target=\"_blank\" rel=\"noopener\">steal credentials<\/a> and even two-factor authentication (2FA) codes. Or they might goal gadget working methods to do the identical. The extra units you&#8217;ve got your password supervisor downloaded to, the extra alternative they&#8217;ve to take action.<\/p>\n<h2>The best way to safe your password supervisor utilization<\/h2>\n<p>To protect in opposition to the threats listed above, think about the next:<\/p>\n<ul>\n<li>Consider a safe, lengthy and distinctive grasp passphrase. Contemplate 4 memorable phrases separated by hyphens. It will make it more durable for an attacker to \u201cbrute pressure\u201d it.<\/li>\n<li>At all times improve the safety of your accounts by switching on 2FA. Because of this even when hackers pay money for your passwords, they will be unable to entry your accounts with out the second issue.<\/li>\n<li>Hold browsers, password managers and working methods updated so they&#8217;re on essentially the most safe variations. This reduces the alternatives for vulnerability exploitation.<\/li>\n<li>Solely obtain apps from a respectable app retailer (Google Play, App Retailer) and test the developer and app score earlier than doing so, in case they&#8217;re faux\/malicious apps.<\/li>\n<li>Solely select a password supervisor from a good vendor. Store round till you discover one you\u2019re snug with.<\/li>\n<li>Make sure you set up safety software program from a good vendor on all units, to mitigate the specter of assaults designed to steal passwords instantly out of your password supervisor.<\/li>\n<\/ul>\n<p>Password managers stay a key a part of cybersecurity greatest apply. However provided that you are taking further precautions. Safety dangers are at all times evolving, so keep abreast of the present risk developments to make sure your on-line credentials keep beneath lock and key.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Look no additional to learn the way cybercriminals might attempt to crack your vault and how one can hold your logins secure 13 Nov 2025 \u00a0\u2022\u00a0 , 5 min. learn The common web person has an estimated 168 passwords for his or her private accounts, in line with a research from 2024. That\u2019s an enormous [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":8762,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[173,648,6440,1631],"class_list":["post-8760","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-hacked","tag-heres","tag-managers","tag-password"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8760","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8760"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8760\/revisions"}],"predecessor-version":[{"id":8761,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/8760\/revisions\/8761"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/8762"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8760"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8760"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8760"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-09 21:22:59 UTC -->