Cyberattack via Chrome extensions: user data stolen

Cyberattack via Chrome extensions: user data stolen
Cyberattack via Chrome extensions: user data stolen

Cyberattack via Chrome extensions: user data stolen

Cybercriminals used malicious code to attack popular Google Chrome browser extensions, resulting in a leak of user data. The stolen information included passwords and cookies, including access to advertising platforms such as Facebook Ads.

How did the attack occur?

According to a report by Cyberhaven, which was one of the victims, the attackers used phishing emails to distribute the malware. The target of the attack was popular Chrome extensions used for VPNs and communications.

Affected applications:

  1. Internxt VPN
  2. VPNCity
  3. Uvoice
  4. ParrotTalks

Consequences and user actions

Cyberhaven stated that it promptly removed the malicious code within an hour of detecting the attack. However, experts warned users of the possible compromise of their accounts.

Protection recommendations:

  • Check your accounts for suspicious activity.
  • Change your passwords, especially on advertising and payment platforms.
  • Ensure that the extensions you use are updated to the latest version.

Risks and conclusions

The incident demonstrates how vulnerable even widely used and trusted applications can be. Users are advised to regularly update their software, avoid clicking on suspicious links, and be mindful of the security of their data.

Cyberhaven emphasised the importance of enhancing security measures and expressed its readiness to cooperate with other companies to prevent similar attacks in the future.

Comments

No comments yet. Be the first!

Leave a comment

Links are not allowed in comments. The editors may remove comments without explanation.
Back to top ↑