1
Published signals
currently linked to this company
Company intelligence
cyberhaven.com
This company page brings together public reporting currently associated with Cyberhaven. It reflects signals published by Shadow Tier and should not be read as a complete incident history.
Company links
1
currently linked to this company
0
recent published signals
0
recent published signals
1
confidence classifications
July 22, 2026
most recent published signal
Explore related intelligence
Based on all published signals currently linked to Cyberhaven. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.
Company signals
Here’s What We Can Learn from the Cyberhaven Incident I. Introduction to the Cyberhaven Security Incident In December 2024, Cyberhaven fell victim to a sophisticated cyberattack that exploited a phishing campaign targeting its Chrome Web Store account. This breach compromised over 400,000 users by injecting malicious code into its browser extension, exfiltrating sensitive data such as cookies and session tokens. The incident has drawn significant attention due to Cyberhaven's role as a cybersecurity provider and the broader implications for browser extension security. This was not a targeted attack on Cyberhaven alone but an opportunistic campaign exploiting multiple developers' credentials - over 35 extensions have been identified as compromised in the same fashion, affecting over 2.6M users. Thus, this is an important and evolving threat that is important to understand and derive lessons from. 1. Initial Attack Discovered - December 24, 2024 The breach began on December 24, when a Cyberhaven employee fell victim to a phishing attack. The attackers used a phishing campaign to compromise an administrative account associated with Cyberhaven's Chrome Web Store. A phishing email , disguised as official communication from Google Chrome Web Store Developer Support, claimed that Cyberhaven's extension violated policies and was at risk of removal. By granting permissions to this application, the attackers gained control of Cyberhaven's Chrome Web Store account . Using this access, they uploaded a malicious version (v24.10.4) of Cyberhaven's browser extension . This version included code to exfiltrate cookies, session tokens, and other sensitive data from users [1][2][4] . The malicious extension passed Chrome Web Store's security review. The attack leveraged OAuth authorization flows which bypassed multi=factor authentication (MFA). Although the employee was using MFA and had enabled Google's Advanced Protection, no MFA prompt was triggered during the OAuth process [7][8] . The malicious code installed took these forms and actions in their environment: Two key malicious files were added [9] .some text worker.js - Connected to C&C server for configuration downloads content.js - Handled data collection and exfiltration When users visited Facebook.com, extension collected [9] some text Facebook access tokens User and account details via Facebook APIs Extension monitored mouse clicks on Facebook.com to detect QR codes [9] Investigations began immediately after the breach was detected on December 25, with Cyberhaven engaging external incident response teams and notifying law enforcement [1][2][3] . 3. Attack Publicly Disclosed - December 27, 2024 Primary targets were Chrome Extension Developers with Facebook Ads account access A number of Cyberhaven's customers were impacted Investigation ongoing with third-party security response team 4. Immediate Breach Impact for Cyberhaven Customers The Cyberhaven breach was part of a broader campaign that targeted at least 35 Chrome extensions, collectively affecting approximately 2.6 million users. This campaign exploited a phishing attack aimed at Chrome extension developers, allowing attackers to gain unauthorized access to their Chrome Web Store accounts and inject malicious code into legitimate extensions.
FAQ
It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Cyberhaven.
No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.
The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.