Skip to main content

Warning: Hackers could take over your email account by stealing cookies, even if you have multi-factor authentication (MFA)

 



The Federal Bureau of Investigation (FBI) has issued a warning that cybercriminals are taking over email accounts via stolen session cookies, allowing them to bypass the multi-factor authentication (MFA) a user has set up.

Here’s how it works.

Most of us don’t think twice about checking the “Remember me” box when we log in. When you log in and the server has verified your authentication—straight away or after using MFA–the server creates a session and generates a unique session ID. This session ID is stored in a session cookie (or a “Remember-Me cookie” as the FBI calls it) on your browser, which is typically valid for 30 days.

Every time you return to that website within the time frame, you don’t need to log in. That’s really convenient… unless someone manages to steal that cookie from your system.

If someone steals the session cookie, they can log in as you—even if you have MFA enabled.

This is particularly relevant for email handlers that have an online—webmail—component. This includes major players like Gmail, Outlook, Yahoo, and AOL.

With access to your email account, a cybercriminal can find a lot of useful information about you, such as where you bank, your account numbers, your favorite shops, and more. This information could then be used for targeted cyberattacks that only mention information relevant to you, leaving you more likely to fall for them.

Cybercriminals could use your account to spread spam and phishing emails to your contacts. And perhaps most worrying of all, once an attacker is in your email account they can reset your passwords to your other accounts and login as you there too.

How do these criminals get their hands on your session cookies? There are several ways.

On very rare occasions, session cookies can be stolen by you visiting a malicious website, or via a Machine-in-the-Middle (MitM) attack where a cybercriminal can intercept traffic and steal cookies if they’re not protected by HTTPS on an unsecured network.

However, session cookies are usually stolen by malware on the your device. Modern information-stealing malware is capable of, and even focuses on, stealing session cookies as part of its activity.  

How to keep your email account safe

There are a few things you can do to stay safe from the cookie thieves:

  • Use security software on every device you use.
  • Keep your devices and the software on them up to date, so there aren’t any known vulnerabilities on them.
  • Decide whether you think it’s worth using the Remember me option. Is convenience worth the risk in this situation?
  • Delete cookies, or—even better—log out when you are done. That should also remove or invalidate the session ID from the server, so nobody can use it to log in, even if they have the session cookie.
  • Only visit sites with a secure connection (HTTPS) to protect your data from being intercepted during transmission.
  • For important accounts regularly check the log in history where you can see which devices logged in when and from where. You should be able to find this option in your account settings.

Comments

Popular posts from this blog

Update: First Responder Credit Unions Academy (FRCUA) Udates

In an ongoing effort to keep your FRCUA education current, modules are continually updated to reflect current NCUA and other regulatory agency requirements. As an example, BSA 26 now includes  Artificial Intelligence and BSA,  Elder Financial Exploitation,  Pig Butchering & BSA, and Executive Order –  Free and Fair Banking.

Mortgage Rates Tick Down

MCLEAN, Va.--Mortgage rates moved slightly lower this week, with the 30-year fixed-rate mortgage averaging 6.56%, Freddie Mac reported. “Mortgage rates are at a 10-month low,” said Sam Khater, Freddie Mac’s chief economist. “Purchase demand continues to rise on the back of lower rates and solid economic growth. Though many potential homebuyers still face affordability challenges, consistently lower rates may provide them with the impetus to enter the market.” The 30-year FRM averaged 6.56% as of Aug. 28, down from last week when it averaged 6.58%. A year ago at this time, the 30-year FRM averaged 6.35%. The 15-year FRM averaged 5.69%, unchanged from last week. A year ago at this time, the 15-year FRM averaged 5.51%, Freddie Mac said. ____________________________________________ Check out NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board

SIGN UP FOR YOUR CUSTOM HEALTH INSURANCE SOLUTION TODAY

 https://bizu65.allstatehealth.com/?password=demo ____________________________________________ Check out NCOFCU's additional features: First Responder Credit Union Academy Podcasts YouTube Mini's Blog Job Board

Many CUs Likely to Face New Operating Challenges "Michael Moebs"

04/08/2024 09:04 pm By Ray Birch LAKE FOREST, Ill.—The trend lines don’t lie: Financial institutions charging high overdraft fees will likely face operating challenges in the near future and may even be forced to merge if they don’t follow the market trend of lowering their OD charge. Michael Moebs, economist and chairman of Moebs $ervices, is offering that forecast following his company’s new overdraft study, which has found overall net OD revenue for 2023 was down 5.7%, with banks dipping by 8.1% to $31.4 billion, thrifts falling by 28.6%. and credit unions actually increasing net revenue 2.2%. The study further reveals the m...

Wendelville Fire Chief Andrew Pilecki re-elected to FASNY board

Andrew Pilecki, the current fire chief of Wendelville Volunteer Fire Company, has been re-elected to the board of directors of the Firefighters Association of the State of New York. Pilecki has been a member of the fire service for more than four decades, including the past 22 years as a responder with the Wendelville company. Previously he was an active member of Columbia Hook and Ladder Co. He’s also a former assistant director of emergency management for the City of North Tonawanda. FASNY directors serve five-year terms of office. During his first term, Pilecki was instrumental in supporting the association’s pandemic response, championed fire company recruitment and retention efforts, and worked to amplify the needs of Western New York’s volunteer fire service at the state level, according to FASNY. “I’m honored to be re-elected and to continue advocating for the men and women who volunteer their time, risk their safety and serve their communities across the state,” Pilecki said. “...