Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Attackers Used Plaxo as Proxy to Hijack Google Accounts

Online Address Book Service Plaxo Switching to oAuth After Being used to Access Google Accounts

Plaxo, a popular online address book service, has disabled its API and suspended some services after attackers used them as a proxy to target an unknown number of Google accounts.

Online Address Book Service Plaxo Switching to oAuth After Being used to Access Google Accounts

Plaxo, a popular online address book service, has disabled its API and suspended some services after attackers used them as a proxy to target an unknown number of Google accounts.

In a blog post, Plaxo, which is a subsidiary of cable giant, Comcast, said that they have disabled the AB Widget function within their API, and started moving all connections to Google over to the more secure oAuth method.

The move to oAuth was previously planned, and is already in use for new users. The AB Widget was slated for end of life late last year. The AB Widget is an API function that enabled websites to import address books from other hosted services, including Google. When it was deployed in 2006, the AB Widget was one of the first applications online to offer such a feature.

“Google and Plaxo detected a malicious party misusing Plaxo’s server connection to Google as a means to login to Google accounts using a set of credentials the malicious party obtained on their own. These credentials were not obtained from Plaxo. This party used a function we call the AB Widget which we had slated for retirement to access those accounts hiding behind Plaxo’s proxy,” Plaxo’s GM Preston Smalley wrote.

The shutdown of all connections to Google from Plaxo was taken as a precaution the blog post added, and will remain so until the transition to oAuth is complete.

“Google Sync will remain disabled until we have the more secure oAuth method available at which point you’ll be notified. This is a top priority for Plaxo, to re-enable Google Sync for our customers.”

It’s unclear how the attackers obtained the Google credentials used in the attack. However, both Plaxo and Google are encouraging anyone who received a notice about the failed access attempt to change their passwords immediately.

Advertisement. Scroll to continue reading.

Looking back, even though the attack was thwarted, it shows that criminals are observant; as they were aware of the Plaxo service and were willing to force them into a middle-man position in order to gain access to additional victims. The overall goal of the attack could be something as small as spam, or depending on the accounts targeted, the initial probe for a larger Phishing attack.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.

Cybercrime

Satellite TV giant Dish Network confirmed that a recent outage was the result of a cyberattack and admitted that data was stolen.