Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Attackers Used Plaxo as Proxy to Hijack Google Accounts

Online Address Book Service Plaxo Switching to oAuth After Being used to Access Google Accounts

Plaxo, a popular online address book service, has disabled its API and suspended some services after attackers used them as a proxy to target an unknown number of Google accounts.

Online Address Book Service Plaxo Switching to oAuth After Being used to Access Google Accounts

Plaxo, a popular online address book service, has disabled its API and suspended some services after attackers used them as a proxy to target an unknown number of Google accounts.

In a blog post, Plaxo, which is a subsidiary of cable giant, Comcast, said that they have disabled the AB Widget function within their API, and started moving all connections to Google over to the more secure oAuth method.

The move to oAuth was previously planned, and is already in use for new users. The AB Widget was slated for end of life late last year. The AB Widget is an API function that enabled websites to import address books from other hosted services, including Google. When it was deployed in 2006, the AB Widget was one of the first applications online to offer such a feature.

“Google and Plaxo detected a malicious party misusing Plaxo’s server connection to Google as a means to login to Google accounts using a set of credentials the malicious party obtained on their own. These credentials were not obtained from Plaxo. This party used a function we call the AB Widget which we had slated for retirement to access those accounts hiding behind Plaxo’s proxy,” Plaxo’s GM Preston Smalley wrote.

The shutdown of all connections to Google from Plaxo was taken as a precaution the blog post added, and will remain so until the transition to oAuth is complete.

Advertisement. Scroll to continue reading.

“Google Sync will remain disabled until we have the more secure oAuth method available at which point you’ll be notified. This is a top priority for Plaxo, to re-enable Google Sync for our customers.”

It’s unclear how the attackers obtained the Google credentials used in the attack. However, both Plaxo and Google are encouraging anyone who received a notice about the failed access attempt to change their passwords immediately.

Looking back, even though the attack was thwarted, it shows that criminals are observant; as they were aware of the Plaxo service and were willing to force them into a middle-man position in order to gain access to additional victims. The overall goal of the attack could be something as small as spam, or depending on the accounts targeted, the initial probe for a larger Phishing attack.

Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.