HomeSecurityPhishing attacks bypass 2-factor authentication

Phishing attacks bypass 2-factor authentication

phishing Don't expect two-factor authentication to always be enough to protect your accounts. Google has seen a worrying increase in phishing attacks that can bypass the security setting.

“We have seen a big spike in the number of 2FA phishing attacks,” said Nicolas Lidzborski, chief security officer for Gmail.

These “2FA phishing attacks” work by tricking the victim into giving up their password and the special one-time password that protects their Gmail account. Normally, this one-time password is difficult to obtain, as it appears on a person’s smartphone and expires after 30 seconds.

However, Lidzborski said hackers have modified their password-stealing programs to also find one-time passwords. The so-called “phishing kits” steal a victim’s password and two-factor authentication code as they type it into deceptive emails and login pages, then gain access to the account within a 30-second time limit.

“2FA is much better than a single factor, which uses just a username and password. There’s no doubt about that,” he said. “However, some hackers try to bypass 2FA.”.

In December, Amnesty International said a hacking group had managed to bypass two-factor protection through an automated phishing attack that could steal and log in with passwords before the 30-second timeout expired. A month later, a security researcher released an open-source toolkit that could also create phishing pages to bypass two-factor.

The fact that the one-time password is sent via SMS doesn't always help. This can make two-factor authentication vulnerable to SIM attacks, in which a hacker can steal the mobile phone number.

During the discussion, Lidzborski said that Google is trying to protect Gmail accounts from successful phishing attacks by blocking login attempts from unknown geographic locations. The company's email service can also warn you about emails that appear to be phishing attempts and about the risks of opening suspicious links within them.

But to stay protected, Lidzborski recommends that users and businesses adopt a hardware-based solution: USB security keys. They work by replacing one-time passwords with a physical piece of hardware that you plug into your computer to access your online accounts. In July, Google said it had given all of its employees security keys.

Unfortunately, security keys aren't cheap. Google's product costs $50 for two keys. However, Lidzborski said they're very effective.

Lidzborski couldn’t quantify the exact increase in these attacks that Google has seen. On average, the company encounters 100 million phishing emails per day. But in the past, only the most sophisticated hackers, such as government spies, used phishing attacks that could defeat two-factor authentication, he said. “Now it’s available as an open-source phishing framework,” he added. “So it’s more prevalent than before.”.

We should always be careful with what we receive in our email inboxes. Phishing emails often look like legitimate services, like Google, and try to trick you into visiting an official login page, when in reality the website is designed to steal your passwords. To teach the public how to spot phishing attacks, Google's Jigsaw last month developed a phishing quiz that can teach you more about the threat.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS