Skip to main content

Warning: Hackers could take over your email account by stealing cookies, even if you have multi-factor authentication (MFA)

 



The Federal Bureau of Investigation (FBI) has issued a warning that cybercriminals are taking over email accounts via stolen session cookies, allowing them to bypass the multi-factor authentication (MFA) a user has set up.

Here’s how it works.

Most of us don’t think twice about checking the “Remember me” box when we log in. When you log in and the server has verified your authentication—straight away or after using MFA–the server creates a session and generates a unique session ID. This session ID is stored in a session cookie (or a “Remember-Me cookie” as the FBI calls it) on your browser, which is typically valid for 30 days.

Every time you return to that website within the time frame, you don’t need to log in. That’s really convenient… unless someone manages to steal that cookie from your system.

If someone steals the session cookie, they can log in as you—even if you have MFA enabled.

This is particularly relevant for email handlers that have an online—webmail—component. This includes major players like Gmail, Outlook, Yahoo, and AOL.

With access to your email account, a cybercriminal can find a lot of useful information about you, such as where you bank, your account numbers, your favorite shops, and more. This information could then be used for targeted cyberattacks that only mention information relevant to you, leaving you more likely to fall for them.

Cybercriminals could use your account to spread spam and phishing emails to your contacts. And perhaps most worrying of all, once an attacker is in your email account they can reset your passwords to your other accounts and login as you there too.

How do these criminals get their hands on your session cookies? There are several ways.

On very rare occasions, session cookies can be stolen by you visiting a malicious website, or via a Machine-in-the-Middle (MitM) attack where a cybercriminal can intercept traffic and steal cookies if they’re not protected by HTTPS on an unsecured network.

However, session cookies are usually stolen by malware on the your device. Modern information-stealing malware is capable of, and even focuses on, stealing session cookies as part of its activity.  

How to keep your email account safe

There are a few things you can do to stay safe from the cookie thieves:

  • Use security software on every device you use.
  • Keep your devices and the software on them up to date, so there aren’t any known vulnerabilities on them.
  • Decide whether you think it’s worth using the Remember me option. Is convenience worth the risk in this situation?
  • Delete cookies, or—even better—log out when you are done. That should also remove or invalidate the session ID from the server, so nobody can use it to log in, even if they have the session cookie.
  • Only visit sites with a secure connection (HTTPS) to protect your data from being intercepted during transmission.
  • For important accounts regularly check the log in history where you can see which devices logged in when and from where. You should be able to find this option in your account settings.

Comments

Popular posts from this blog

World's Happiest Country

  World's Happiest Country   Finland was named the world’s happiest country for the ninth consecutive year, the latest World Happiness Report revealed. Nordic countries—including Denmark, Iceland, Norway, and Sweden—also ranked in the top 10.  Analysts attribute Finland’s joy factor to its wealth, social safety network, and high life expectancy, among factors. Afghanistan maintained its place as the world’s unhappiest country. The results were based on answers from roughly 100,000 people in 140 countries and territories. Respondents were asked to rank their life satisfaction on a scale of 0 to 10. Finnish respondents gave an average life satisfaction score of 7.7; Afghans answered 1.4. The US, in 23rd place, reported an average score of 6.8. Explore rankings here . The report's authors cautioned this year that social media use is driving population-level drops in reported well-being among adolescents. Young English...

Regulators Launch Broad Rewrite Of Bank Capital Rules, Eye Lower Requirements

WASHINGTON— Federal banking regulators on Thursday formally launched what could become the biggest rewrite of U.S. bank capital rules in years, unveiling a package of proposals aimed at easing and recalibrating capital requirements across the industry—moves officials say should reduce aggregate required capital for banks of all sizes and free up more capacity for lending. The Federal Reserve and FDIC both advanced the proposals at board meetings Thursday, while the OCC joined the interagency package, Law360 reported. At the center of the package is a long-awaited rewrite of the U.S. “Basel III endgame” proposal for the largest banks, along with a broader companion proposal to make risk-based capital rules more risk-sensitive for smaller and midsize banks as well. Bloomberg reported the changes are designed to relax capital treatment for large lenders, while Law360 said regulators described the package as a comprehensive overhaul intended to finish the delayed Basel implementation and r...

Average 30-Year Fixed-Rate Mortgage At 6.22%

MCLEAN, Va.--The 30-year fixed-rate mortgage inched up this past week, averaging 6.22%, Freddie Mac reported. "The 30-year fixed-rate mortgage edged up this week to 6.22% but remains nearly half a percentage point lower than the same time last year," said Sam Khater, Freddie Mac's chief economist. "Potential homebuyers are poised for a more affordable spring homebuying season than last with the market experiencing improvements in purchase applications and pending home sales.” The 30-year FRM averaged 6.22% as of March 19, up from last week when it averaged 6.11%. A year ago at this time, the 30-year FRM averaged 6.67%. The 15-year FRM averaged 5.54%, up from last week when it averaged 5.50%. A year ago at this time, the 15-year FRM averaged 5.83%. ================================================= Remember, you're not alone with  NCOFCU.org Join/Upgrade Check out some of NCOFCU's additional features: Annual Conference First Responder Credit Union Academy Finan...

Sunday Reading - March Madness, explained

  The Big Dance   March Madness, explained "March Madness" is the well-known name for the NCAA's annual Division I men's and women's basketball tournaments, which determine national champions through a 68-team , single-elimination format. Automatic bids go to 31 conference winners, while 37 at-large selections fill the field. The high-stakes structure—where smaller "Cinderella" schools can upset powerhouses—drives huge viewership and revenue; TV and marketing rights account for roughly two-thirds of the NCAA's $1.4B income in fiscal 2024. The National Inv...

James Hunter, Executive Director of Credit Union Development for New Orleans Firemen’s CU, knows too well how expensive it is to be poor.

  NEW ORLEANS FIREMEN’S FCU 􀀁 METAIRIE, L   A passion for empowerment James Hunter knows too well how expensive it is to be poor. It’s what he sees every day as mortgage director and executive director of credit union development for $182 million asset New Orleans Firemen’s Federal Credit Union, Metairie, La., and executive director of The Faith Fund, a nonprofit partnership that seeks to provide a financial hand-up to the undeserved. It’s what inspires him to come to work every day and drives his passion of empowering people and setting them on the path to financial security. “Too many people are too far away from the starting line,” Hunter says. “Payday loans are a big business in Louisiana. Exorbitant fees and interest from payday loans drain more than a quarter of a billion dollars a year. Baton Rouge supports one of the top three pay-day loan markets in the U.S.” The Faith Fund was formed to counteract that. It’s a unique cooperative relationship between like-minded busi...

FRB decided to maintain the target range for the federal funds rate at 3‑1/2 to 3‑3/4 percent

  Federal Reserve issues FOMC statement For release at 2:00 p.m. EDT Share Available indicators suggest that economic activity has been expanding at a solid pace. Job gains have remained low, and the unemployment rate has been little changed in recent months. Inflation remains somewhat elevated. The Committee seeks to achieve maximum employment and inflation at the rate of 2 percent over the longer run. Uncertainty about the economic outlook remains elevated. The implications of developments in the Middle East for the U.S. economy are uncertain. The Committee is attentive to the risks to both sides of its dual mandate. In support of its goals, the Committee decided to maintain the target range for the federal funds rate at 3‑1/2 to 3‑3/4 percent. In considering the extent and timing of additional adjustments to the target range for the federal funds rate, the Committee will carefully assess incoming data, the evolving outlook, and the balance of risks. The Committee is strongly com...

What Trump’s ‘one big beautiful’ tax-and-spending package means for your money!

  Trump’s megabill will bring sweeping changes for household finances. President  Donald Trump  signed his “one big beautiful” tax-and-spending package on July 4 — legislation that will bring sweeping changes to Americans’ finances.  After the  Senate passed its version  on July 1, the House Republicans on July 3  voted to approve  the multi-trillion-dollar domestic policy legislation and send it to Trump’s desk for signature. The final bill makes permanent Trump’s  2017 tax cuts  while adding new relief, including a senior “bonus” to  offset Social Security taxes  and a  bigger state and local tax deduction . The plan also has tax breaks for  tip income , overtime pay and  auto loans , among other provisions.  The GOP’s marquee legislation will also enact deep spending cuts to social safety net programs such as  Medicaid  and food stamp benefits,  end tax credits tied to clean energy  an...

A Perfect Example - What Makes Credit Unions Different from Banks!

When the government shutdown hit in October and paychecks stopped, thousands of federal employees were left wondering how to make ends meet. Credit unions across the country stepped up—but Keesler Federal Credit Union went above and beyond. No loans, no hassle—just your paycheck Instead of making members apply for emergency loans, Keesler Federal launched its Paycheck Relief Program. Revolutionary in its simplicity, it worked like this: if you were a federal employee with direct deposit at Keesler Federal, your paycheck kept coming—interest-free, fee-free, and stress-free. Each qualified member could receive up to $6,000 per pay period for as long as 90 days. No hoops, no headaches. From October 1 until the shutdown ended, Keesler Federal advanced more than 5,000 paychecks totaling $6.5 million to 1,710 members. For non-members, they even offered zero-interest loans up to $6,500 with a year to pay it back. This proactive approach meant that before the first missed paycheck, Keesler Fed...

Lifesaving Companion Dog Takes On New Role With Injured Firefighter « CBS New York

Lifesaving Companion Dog Takes On New Role With Injured Firefighter « CBS New York : "NEW YORK (CBSNewYork) — A badly injured New York firefighter received a companion dog whose already saved people’s lives from fire. As CBS2’s Dave Carlin reported, disabled firefighter Tom Prin beamed as he was officially presented with his new canine companion Halona inside of a packed ceremony in Suffolk County. The former firefighter was one of 15 people receiving their canine companions. Prin was chosen because of what he’s been through — after fracturing his neck and back while responding to a Brooklyn fire. “When I was going from the third to fourth floor, the steps gave out and I fell through the fire escape,” he said. Prin has endured five spinal surgeries, but the Holtsville man will now be comforted by Halona who has quite the lifesaving resume herself." Click HERE to read full story and see video 'via Blog this'