Passwordstate users told to reset passwords following security breach

Scammers
(Image credit: Pixabay)

Users of enterprise password management platform Passwordstate have been warned to reset all the passwords contained within the tool.

Developer Click Studios has issued a warning confirming that attackers managed to compromise a patch for the Passwordstate platform. As users installed the patch, they were also unwittingly installing password-stealing malware which sent sensitive information back to its command & control server.

The campaign was allegedly active between April 20-22, and while Click Studios claims the servers have been knocked offline, criminals could still use the stolen data, should they bring the server back online.

The company did not elaborate on exactly how the criminals managed to breach their systems and compromise the patching feature, but they did email their customers with a cybersecurity fix.

While Click Studios said the number of affected organizations was relatively low, it still urged everyone to change their credentials as soon as possible. This could prove difficult however, as most of its clients are organizations that also store firewall and VPN passwords in the software.

Passwordstate

Password managers are small tools, usually embedded within browsers, that store login credentials for users. That way, they don’t have to put their organizations at risk by using the same credentials across different services, writing down passwords on pieces of paper or on their computer, or by setting weak passwords that are easy to remember. 

They can also be used to create strong passwords and to force users to update their passwords regularly. 

According to TechCrunch, Click Studios’ Passwordstate is currently used by more than 29,000 customers, including Fortune 500 organizations, various government institutions, banks, defense and aerospace organizations, and “most major industries”.

The affected customers were notified in a timely manner, but the media only picked up on it a few hours later, when a cybersecurity firm CSIS Group detailed the attack in a blog post.

Click Studios is yet to comment on the breach, but has been contacted for comment.

Via: TechCrunch

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
A worrying Apple Password App vulnerability reportedly left users exposed for months
A hand laying out a password
Security attacks on password managers have soared
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
Latest in Security
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
Zendesk Relate 2025
Zendesk Relate 2025 - everything you need to know as the event unfolds
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Google Gemini AI
Gemini can now see your screen and judge your tabs
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand