CYBER WELFARE

Protect your Digital Privacy

Attacks on password vaults: how they work and how to defend

A credential store is a valuable target. It would be naive to claim otherwise, and equally naive to conclude that it is therefore better not to use one.

The honest position is a third one: understand how people try to get in, because almost every route passes through two points that depend on you — the master password and the second factor.

This post describes the relevant attacks from the point of view of the person on the receiving end, so they can be recognised and defended against. It contains no operational instructions. It is the threat-side companion to the recommendation storing passwords safely.

The starting point

A well-designed vault does not keep your master password and cannot read your store. It follows that anyone wanting to reach it has three possible routes:

  1. obtain the master password — by convincing you to type it, or by finding it already exposed elsewhere;
  2. act on your device — where the store, while unlocked, is in the clear;
  3. take the encrypted store — from a provider breach, and try to open it.

These routes differ enormously in difficulty and in frequency. We look at them in order of how often they actually happen.

1. Phishing aimed at the master password

In plain terms. A message or a page imitating your vault asks you to type the master password.

How it works. An alert arrives — “suspicious activity on your vault”, “verify your account”, “your licence is about to expire” — with a link to a page that looks very much like the real one. Whoever built the page receives what you type.

Why it is first on the list. It is by far the most common attack against vaults, because it does not require breaking any encryption: it simply asks the key from the person who holds it.

Possible impact. With no second factor, immediate access to the store.

What should make you suspicious. Urgency, a sender address that does not match, a similar but not identical domain, a request for the master password by message. And above all: your vault does not autofill on that page, because the address is not the registered one.

How to protect yourself. Never sign in from a link you received: open the app or type the address you normally use. No serious vault asks for the master password by email. And keep the second factor on: it makes stealing the password alone insufficient.

2. Reusing the master password

In plain terms. The master password — or a variant of it — had already been used on another service, and that service was breached.

How it works. The credential list circulates, and gets tried against the best-known password vaults too. If the pair works, the store opens.

Why it happens. Because the master password is often chosen before understanding how important it is, reusing a passphrase already in service, perhaps with a small tweak.

Possible impact. Access to the store without anyone having had to attack the vault at all.

What should make you suspicious. Failed sign-in attempts, verification requests you did not start, exposed-password alerts concerning that passphrase.

How to protect yourself. The master password must be absolutely unique: never used anywhere else, in any variant. It is the rule of recommendation R1 applied to the single most important credential you hold.

3. Prompted approval of the second factor

In plain terms. Somebody already has the master password and sends you confirmation requests until you approve one.

How it works. The notifications arrive repeatedly, often at night or at distracted moments. One approval by mistake is enough. In some variants a fake support call also arrives, asking you to “confirm so we can close the report”.

Why it works. It does not attack the technology: it attacks tiredness and the habit of approving.

Possible impact. Full access to the store, despite the second factor being enabled.

What should make you suspicious. Verification requests you did not start, especially repeated ones. Any contact asking you to approve one.

How to protect yourself. Never approve a request you did not start — and treat it as a signal: it means the master password is known. Change it immediately. Where available, prefer a second factor that requires typing a number shown on screen, rather than a simple “approve”.

4. Unwanted software on the device

In plain terms. A program installed on your device watches what you type, or reads the store while it is unlocked.

How it works. It arrives through software downloaded outside official channels, through browser extensions with little transparency, or through attachments opened without checking.

Why it matters. It is the one scenario in which encryption does not help: when the store is open, its contents are in the clear on the device.

Possible impact. Capture of the master password and of the store’s contents.

What should make you suspicious. Unusual slowdowns, odd battery consumption, extensions or apps you do not remember installing.

How to protect yourself. Operating system up to date (R6), software only from official sources, few extensions and all recognisable, vault auto-lock set to a few minutes.

5. Physical access to the device

In plain terms. Somebody uses your device while the store is unlocked.

How it works. No skill required: a computer left open in a shared space, an unlocked phone, an unattended desk.

Why it matters. It is the most mundane attack and, in shared environments, one of the most realistic.

What should make you suspicious. The vault turns out to be unlocked when you do not recall opening it; recently viewed entries you did not open.

How to protect yourself. Automatic screen lock (R7) and vault locking after a few minutes of inactivity. Two settings, and they cover almost the whole scenario.

6. Provider breach

In plain terms. The service holding the encrypted stores suffers an incident, and those stores end up in someone else’s hands.

How it works. Whoever obtains an encrypted store has nothing readable yet: they have to try to derive the key, which means guessing the master password. The key derivation process is designed to make each attempt expensive.

Why the master password decides everything. With a long, unique passphrase, the time required stays out of reach. With a short password, or one that has appeared elsewhere, the protection thins out considerably.

Possible impact. In the worst case, exposure of the credentials held. Even without opening the store, some metadata — such as the addresses of the services you use — may turn out to be more exposed.

What should make you suspicious. Official communications from the provider. Note carefully: after a well-known incident, fake alerts exploiting it also increase.

How to protect yourself. A long, unique master password; if an incident notice arrives, change it and change the credentials of your critical accounts. And verify the news on the official site, not from links you received.

7. Fraudulent browser extensions

In plain terms. An extension imitating a password vault, or inserting itself into the autofill process.

How it works. It is published with a name and an icon very close to those of a well-known tool, and asks for broad permissions over the pages you visit.

Why it works. Because it gets installed voluntarily, by someone looking for exactly that tool.

Possible impact. Capture of credentials at the moment of autofill.

What should make you suspicious. Extensions with few users and a name almost identical to the original; disproportionate permissions; an extension appearing that you do not recall installing.

How to protect yourself. Install the extension starting from the vault’s official website, not by searching the store. Review your active extensions periodically and remove those you do not recognise.

Summary table

AttackWhat it depends onWhat should make you suspiciousEffective defences
Phishing for the master passwordYouUrgency, similar domain, the vault does not autofillSign in only from the app or usual address; MFA
Reusing the master passwordYouFailed attempts, exposed-password alertsAn absolutely unique master password
Prompted MFA approvalYouVerification requests you did not start, repeatedNever approve; change the password at once
Unwanted softwareThe deviceSlowdowns, unknown apps or extensionsUpdates, official sources, auto-lock
Physical accessThe settingStore found unlockedShort screen lock and vault lock
Provider breachThe providerOfficial communicationsLong, unique master password; change after the incident
Fraudulent extensionYouSimilar name, few users, broad permissionsInstall from the official site; review periodically

Why the store is almost never the direct target

A detail that helps put things in proportion: none of the seven attacks tries to break the encryption.

Six out of seven go through the person — a credible message, a password already exposed, an approval given out of tiredness, an extension installed voluntarily, a device left open. The seventh, the provider breach, tries to guess the master password, not to force the algorithm.

That is no coincidence. Modern encryption, properly applied, is the most solid part of the system; it is far more economical to ask the key from the person who holds it.

From which the practical conclusion: the quality of your master password and your habit of not approving unexpected requests are worth more than any technical feature of the tool.

The most delicate moment: right after a well-known incident

Worth isolating, because that is when defences drop.

When a provider breach becomes news, people using that service are expecting communications — and that is exactly what makes the messages imitating them so effective. In the days after a public incident, emails arrive that look like the official notice, with a link to “verify your account” or “reset your master password”.

How to handle it:

  • verify the news on the official site, typing the address, never from links you received;
  • change the master password from the app, not from a page reached through a message;
  • be wary of any confirmation request arriving in those days: that is when they are attempted most;
  • do not rush: no legitimate alert asks you to act within minutes.

The same principle applies more broadly: urgency is almost always part of the scam, not of authentic communication.

What they have in common

Five attacks out of seven stop with two measures:

  1. A unique, long master password, never used anywhere else in any variant.
  2. An active second factor, never approved out of habit.

The third measure, which covers the two remaining scenarios, is keeping the device clean: updates, software from official sources, few extensions.

None of these requires technical skill. All of them require being done once and not undone for convenience.

Protection checklist

  • ☐ The master password has never been used elsewhere, in any variant
  • ☐ It is a long passphrase, with no personal references
  • ☐ The second factor is enabled on vault access
  • ☐ I never approve verification requests I did not start
  • ☐ I only reach the vault from the app or the address I normally use
  • ☐ The browser extension was installed from the official site
  • ☐ Vault auto-lock is set to a few minutes
  • ☐ The device is up to date and has no unknown apps or extensions

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that almost every attack goes through the person, not the encryption
SkillsTelling a legitimate alert apart from one imitating it
Secure BehaviourNot approving out of habit; always signing in through the usual channel

Reference level: FL3 — Autonomous.

Conclusion

The encryption in a password vault is not the weak point. The weak point is the moment a person types the master password where they should not have, or approves a request they did not start.

That is good news: it means the defence is within anyone’s reach, and does not depend on complicated technical choices.

Something to think about. If you got a notification right now asking you to confirm access to your vault, could you say with certainty whether you had started it?

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.