- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,455
What is called a defense in the “corporation of good” is considered the main “gift of fate”.

One short PIN code can turn Google’s password storage into an open door for attackers. The new VaultJacking phishing technique shows that even logging on access keys does not save if the attacker does not get to a separate site, but to the mechanism of synchronization of accounting data.
According to PhishU experts, the attack is being built on the Adversary-in-the-Middle scheme, when the victim is transferred to a fake but plausible entry page of Google. During such a session, attackers intercept logins, password, session cookies and six-digit PIN Google Password Manager.
PIN is the main link of the attack. After receiving the code, the attackers can add their device to the list of trusted Google accounts. After connecting, the system issues a secret key of the trusted area. With this key, attackers can decrypt stored passwords and access key data (passkeys).
Unlike conventional phishing, where criminals steal access to one service, VaultJacking gives a chance to unload all synchronized storage at once. Posts, bank offices, corporate systems and cryptocurrency platforms are at risk if the data from them is stored in the Google account.
PhishU claims that the scheme also works against accounts where access keys are used, including hardware protection options. The keys themselves do not break: the binding of WebAutn to the domain continues to protect the entry into specific sites. VaultJacking bypasses this level because it attacks the synchronization of the repository, not the authorization process on a separate resource.
After receiving a PIN, attackers can register their own access key in the victim’s account, log in with it and connect their device to the trusted area of Google through the controlled infrastructure. At the same time, the victim sees a minimum of signals: usually there are letters about a new input or added key, but without a separate confirmation request from a trusted device. If the criminals already control the mail, such notifications can be hidden.
The authors of the report attribute the risk to the fact that Google allows the connection of the new device through a short PIN without mandatory approval from an already trusted device. Apple’s iCloud Keychain similar access requires explicit confirmation, which reduces the value of the intercepted code.
For companies using Google Workspace, PhishU advises closely tracking the addition of new devices and viewing events such as a possible sign of hacking. Individual Chrome work and personal profiles Chromealso reduce damage if one account is attacked.

One short PIN code can turn Google’s password storage into an open door for attackers. The new VaultJacking phishing technique shows that even logging on access keys does not save if the attacker does not get to a separate site, but to the mechanism of synchronization of accounting data.
According to PhishU experts, the attack is being built on the Adversary-in-the-Middle scheme, when the victim is transferred to a fake but plausible entry page of Google. During such a session, attackers intercept logins, password, session cookies and six-digit PIN Google Password Manager.
PIN is the main link of the attack. After receiving the code, the attackers can add their device to the list of trusted Google accounts. After connecting, the system issues a secret key of the trusted area. With this key, attackers can decrypt stored passwords and access key data (passkeys).
Unlike conventional phishing, where criminals steal access to one service, VaultJacking gives a chance to unload all synchronized storage at once. Posts, bank offices, corporate systems and cryptocurrency platforms are at risk if the data from them is stored in the Google account.
PhishU claims that the scheme also works against accounts where access keys are used, including hardware protection options. The keys themselves do not break: the binding of WebAutn to the domain continues to protect the entry into specific sites. VaultJacking bypasses this level because it attacks the synchronization of the repository, not the authorization process on a separate resource.
After receiving a PIN, attackers can register their own access key in the victim’s account, log in with it and connect their device to the trusted area of Google through the controlled infrastructure. At the same time, the victim sees a minimum of signals: usually there are letters about a new input or added key, but without a separate confirmation request from a trusted device. If the criminals already control the mail, such notifications can be hidden.
The authors of the report attribute the risk to the fact that Google allows the connection of the new device through a short PIN without mandatory approval from an already trusted device. Apple’s iCloud Keychain similar access requires explicit confirmation, which reduces the value of the intercepted code.
For companies using Google Workspace, PhishU advises closely tracking the addition of new devices and viewing events such as a possible sign of hacking. Individual Chrome work and personal profiles Chromealso reduce damage if one account is attacked.