Understanding & Preventing Tabnabbing

Written By: Andre Perreault

TL;DR: Tabnabbing targets inactive browser tabs, lures you to a fake login portal, and steals your credentials. Adding this code “_blank” rel=”noopener noreferrer” to link tags prevents the attacks.

In the cybersecurity world, we often worry about the common issues such as ransomware locking a database or a large server breach. However, tabnabbing is a much more subtle phishing tactic that relies on a user’s trust and inattention to their open browser tabs.

What Is Tabnabbing?

Tabnabbing is a phishing attack that targets inactive browser tabs. Unlike a traditional attack which lures you to a fake site via email, tabnabbing waits for you to make the first move. Here’s how this tactic works:

  1. The Bait: A user opens a seemingly harmless website, like Facebook or a hospital’s patient login page.
  2. The Wait: The user switches to another tab to continue working. While the first tab is open in the background it triggers a malicious script.
  3. The Switch: The inactive tab automatically rewrites itself to be an exact clone of the trusted login page, such as Facebook or a hospital portal login.
  4. The Catch: When the user clicks back to the idle tab, they assume they were timed out or logged out. Seeing a familiar login screen, they enter their credentials, which are immediately sent to the attacker.

Why Hospitals Are Prime Targets

Hospitals are high-pressure and fast-paced environments, making them vulnerable to this specific phishing attack. Here’s why hospitals are prime targets:

  • The “Timeout” Expectation: Healthcare portals are supposed to log you out after inactivity in compliance with HIPAA. Attackers use this to their advantage since users wouldn’t think twice about logging back into a portal they know has most likely kicked them out before.
  • The Permanence of Protected Health Information (PHI): A stolen credit card can be cancelled, but stolen records are permanent. Once attackers access the patient portal, they gain social security numbers, home addresses, insurance details, and sensitive medical notes. This holds value in the wrong hands, and in some instances, the info can be sold as a commodity.
  • Trusted Institutional Branding: Attackers target hospital sites because patients have a high level of trust in their hospital’s digital identity. Users are less likely to question the URL of a tab they know they opened compared to receiving a link in a suspicious email.

Pero SEO’s Primary Research Findings

Pero SEO conducted an audit on the top ten children’s hospitals in the U.S. and found that 70% of the patient portals were vulnerable to tabnabbing.

Hospitals Vulnerable to Tabnabbing Table

Figure 1: Spreadsheet of the Number of Hospitals That Are Vulnerable to Tabnabbing.

How to Fix Tabnabbing

Although this information sounds terrifying, there is a straightforward fix for your development team to ease your worried thoughts!

If you have links on your website that open in another tab, have your developers add this code “_blank” rel=”noopener noreferrer” to the link tags. The “_blank” makes the page open in a new tab, and the rel=”nooperner noreferrer” prevents that tab from being tabnabbed.

Request an Audit to See If Your Website Is Protected!

Are you concerned about your facility’s vulnerability to tabnabbing? Don’t wait for a break to find out where your weak spots are. Reach out with the form below!

 


Add Pero SEO as a preferred source to your Google searches to find more healthcare marketing strategies.

Latest Article

Resources

Spread the word!

Border Collie Wagging Tail with a Blue Stethoscope Below Him

Get In Touch

Go to Top