Anya Berkut / Getty Images
Password managers are one of the most effective ways internet users keep their online lives in order. Many popular services include 1Password, LastPass, and NordPass, which can be used for storing and generating passwords, and recalling login credentials.
However, while you may think your passwords are secure with these platforms, cybercriminals are getting more sophisticated with their methods of hacking password managers and getting access to your digital information.
A recent report by cybersecurity firm Picus Security indicates cyberattacks on password managers were three times more likely to occur in 2024 than in the year prior.
The research, detailed in the firm’s Red Report 2025 also noted that of the one million malware variants studied, 25% of them targeted password managers or some method of other password storage, such as web browsers that allow for saving login credentials.
“For the first time ever, stealing credentials from password stores is in the top 10 techniques listed in the MITRE ATT&CK Framework,” Picus Security said in a press release. “The report reveals that these top 10 techniques accounted for 93% of all malicious actions in 2024.”
The firm uses its MITRE ATT&CK Framework to classify cyberattacks. Picus has determined that hackers have developed a multi-stage method of cyberattack it’s calling “SneakThief,” which entails “increased stealth, persistence, and automation.” Hackers perform over a “dozen malicious actions” to collect data without detection. Picus calls the method “the perfect heist.”
“Threat actors are leveraging sophisticated extraction methods, including memory scraping, registry harvesting, and compromising local and cloud-based password stores, to obtain credentials that give attackers the keys to the kingdom,” Picus Security co-founder and VP of Picus Labs, Dr. Suleyman Ozarslan said in a statement.
Ozarslan recommends that password manager users utilize multi-factor authentication alongside the primary password-storing method. Additionally, he suggests never reusing passwords, particularly if they are being stored in a password manager.
While artificial intelligence is a quickly growing trend in today’s cybersecurity space, Red Report noted no significant increase in cybercriminals using AI-driven malware in 2024.
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
5 password managers you should use instead of LastPass
When it comes to securing your passwords, LastPass has been one of the top contenders as the best password manager. However, a recent set of high-profile security incidents has made a lot of people a lot less willing to trust it.
If you’re looking for an alternative to LastPass, you’re in the right place. We’ve found five superb password managers that can keep you safe online without the hassle.
1Password
Read more
Why 1Password continues to beat its biggest rivals
The best password managers help bridge the gap between devices and people. Instead of walled gardens and sharing hassles, top-rated solutions from 1Password and Dashlane can bring order and simplicity to login management.
I recently reviewed two of the most popular password managers and can share some insights about their unique features to help you choose the one that best suits your needs.
Tiers and pricing
A side-by-side comparison of 1Password and Dashlane pricing. Digital Trends
Read more
I reviewed two of the best password managers. Here’s the one I recommend people use
If you need more convenience, protection, and cross-platform integration than you can get with your browser’s autofill, you need a premium password manager like 1Password or Bitwarden. I recently reviewed both and put together this comparison to help you pick which works best for you.
Tiers and pricing
A side-by-side comparison of 1Password and Bitwarden pricing. Digital Trends
1Password is only available as a subscription, but Bitwarden has a very good free version. If you don’t want to pay an annual fee to use a password manager, Bitwarden is a great choice.
Read more
GIPHY App Key not set. Please check settings