Skip to Content

2. Fake Password Managers: How One Hid for a Year

LESSON 2 OF 7 · 8 MIN

Fake Password Managers: How One Hid for a Year

This is the most important lesson in the course, because it breaks an assumption almost everyone holds: “if something bad were installed, my antivirus would have told me”.

A business owner asked us to look at her accounts after her Microsoft password suddenly stopped working. Her laptop had already been scanned — properly, from outside the running system — and it came back clean. No viruses, no remote-access tools, nothing hidden on the disk. That result was correct.

What the scan did not cover

It did not look at browser extensions. And that is where the problem was.

Installed in her browser was an extension calling itself a well-known password manager, with the right name and the right icon. It was a counterfeit — a different publisher, a different extension ID, installed not from the official store but from an installer file downloaded off a website.

The timeline is what makes this lesson land
  • The fake manager was installed more than a year before we found it.
  • It rode browser sync onto her brand-new laptop — a clean machine inherited a compromised extension automatically.
  • A matching fake “VPN” extension came with it.
  • Every password she typed for a year passed through software controlled by somebody else.
Why the antivirus stayed silent

Because an extension is not a virus on the disk. It is a small program living inside the browser, installed with your permission. Antivirus looks for malicious files — this was a legitimate-looking add-on doing exactly what you allowed it to do: read what you type.

The rule that follows from this

You install a password manager only from the link GNSIT gives you — never from a search result, never from an installer someone sent, never from an advert. And a new computer does not inherit safety from being new, if it syncs a browser profile from the old one.

Commenting is not enabled on this course.