HomeSecurityHackers compromise email accounts with MFA by stealing cookies

Hackers are breaching email accounts with MFA by stealing cookies

Cybersecurity researchers at Malwarebytes have revealed that hackers can hack MFA-enabled email accounts by stealing cookies.

See also: Hackers steal cookies to gain access to your accounts

MFA cookies

Implementing MFA reduces the risk of unauthorized access, making it a critical security measure for protecting sensitive information in email accounts.

Hackers have started stealing session cookies to bypass multi-factor authentication (MFA). When you log in to any website, the server generates a unique session ID, which is stored in your browser as a cookie-tagged session.

This cookie typically has a lifespan of 30 days and acts as a login beacon, helping you log in without hassle. However, if a threat actor steals these session cookies, they can use them to grant themselves access to the account, even when MFA is in place, the report.

See also: Tool bypasses Google Chrome's new cookie encryption system

This is because the stolen cookie contains valid session information, which allows the attacker to bypass the additional authentication step required by MFA.

Hackers are breaching email accounts with MFA by stealing cookies

In its most recent presentation, the FBI said that user accounts were at serious risk from actors exploiting this vulnerability. When a malicious actor gains unauthorized access to an email account, the criminal uncovers a treasure trove of sensitive information, including credit card numbers and addresses used in online stores.

One important technique is to hack session cookies and other data. Session cookies are small pieces of data that browsers to maintain a user's login status across different pages or sessions.

Once hackers obtain these session cookies, they can use the victim's MFA-enabled email account without needing the actual login and password.

See also: Infostealer bypasses Chrome's new cookie theft defenses

In the digital world, hackers often engage in activities such as cookie theft to gain unauthorized access to user accounts. When a hacker captures these cookies, often through techniques such as hijacking or cross-site scripting (XSS), they can impersonate the user, bypassing security measures. This type of cyberattack highlights the importance of strong cybersecurity practices, including using secure connections, regularly expiring cookies, and educating users about potential phishing, to protect personal and sensitive data online.

Source: cybersecuritynews

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS