Increased attacksThis popular protection method does not necessarily protect against hackers
Martin Abgottspon
18.2.2025
Strong passwords are more important than ever in the age of AI.
Reddit
Password managers offer many advantages. You only have to remember one master password and are generally more secure. But this is only true to a limited extent, as increasing hacker attacks show.
18.02.2025, 14:30
18.02.2025, 16:22
Martin Abgottspon
No time? blue News summarizes for you
Cyberattacks on password managers have tripled, especially due to the new "SneakThief" malware.
Experts recommend strong, individual passwords and advise against saving them in the browser.
Password lists as an alternative: one part of the password is written down, the other is kept in your head.
As a recent analysis by IT security company Picus Security shows, cyberattacks on password managers have tripled in the past year. Popular applications such as 1Password, LastPass and NordPass, which are used by millions of people, are particularly affected. According to the study, which examined over one million different malware variants, 25 percent of all attacks are now targeted at password managers or access data stored in the browser. For the first time, this type of attack is one of the ten most frequently used cyberattacks worldwide.
Of particular concern is the new "SneakThief" attack method, a multi-stage malware characterized by increased stealth and automation. It enables cyber criminals to extract data undetected and reuse it. If an attack is successful, hackers not only gain a single password, but potentially access to all of a user's online accounts.
How can you protect yourself?
Security experts recommend consistently following the well-known basic rules for secure passwords:
The basics of secure passwords
Length and complexity: A secure password should be at least 16 characters long and contain a combination of upper and lower case letters, numbers and special characters.
Individual passwords: A unique password should be used for each account to minimize the risk of a "domino effect" in the event of data leaks.
No saving in the browser: Many users save their access data in their web browser - a risky practice as these are also increasingly being attacked.
If you have been using password managers up to now, you don't have to stop using them completely. However, a conscious approach to passwords as a supplement certainly does no harm. A possible alternative for creating passwords could be the password list concept.
In this case, only the second part of a password is saved, while the first part is remembered on the basis of an individual mnemonic phrase. For example, the password "IfmalmdFiB,ufzb" could be derived from the sentence "I prefer to cycle to the office in the morning to stay fit". In combination with an individual addition - such as "45Social!?" for Instagram - this creates a secure and unique password.
If you take such measures, the use of password managers is also no problem. In addition to strong passwords, you should ideally also activate two-factor authentication where possible.