Skip to main content
  1. Home
  2. Computing
  3. News

Hackers are using cookies to sidestep two-factor authentication

Add as a preferred source on Google

“Cookie stealing” is among the latest trends in cybercrimes that hackers are using to bypass credentials and access private databases, according to Sophos.

Typical security advice for organizations has been to move their most sensitive information to cloud services or to use multifactor authentication (MFA) as a safety means. However, bad actors have figured out how to swipe cookies connected to login details and replicate them to hack the active or recent web sessions of programs that are not commonly refreshed.

A large monitor displaying a security hacking breach warning.
Stock Depot / Getty Images

These hackers are able to exploit several different online tools and services, including browsers, web-based applications, web services, malware-infected emails, and ZIP files.

Recommended Videos

The most insidious aspect of this style of hacking is that cookies are so widely used that they can help nefarious users access systems even if safety protocols are in place. Sophos noted that the Emotet botnet is one such cookie-stealing malware that targets data in the Google Chrome browser, such as stored logins and payment card data, despite the browser’s affinity for encryption and multifactor authentication.

On a broader scale, cybercriminals can purchase stolen cookies data, such as credentials from underground marketplaces, the publication said. The login details for an Electronic Arts game developer ended up on a marketplace called Genesis, which was reportedly purchased by the extortion group Lapsus$. The group was able to replicate EA employee login credentials and ultimately gain access to the company’s networks, stealing 780 gigabytes of data. The group collected game and graphics engine source code details that they used to try to extort EA.

Similarly, Lapsus$ hacked the databases of Nvidia in March. Reports claimed the breach might have revealed the login information of more than 70,000 employees, in addition to 1TB of data from the company, including schematics, drivers, and firmware details. However, there is no word as to whether the hack was due to cookie stealing.

Other cookie-stealing opportunities might be easy to crack if they are software-as-a-service products, such as Amazon Web Services (AWS), Azure, or Slack. These can start with hackers having basic access but tricking users into downloading malware or sharing sensitive information. Such services tend to remain open and running persistently, meaning their cookies don’t expire often enough to have their protocols to be sound security-wise.

Sophos notes that users can regularly clear their cookies to maintain a better protocol; however, that means having to reauthenticate each time.

Fionna Agomuoh
Fionna Agomuoh is a Computing Writer at Digital Trends. She covers a range of topics in the computing space, including…
Gemini is moving into Google Play, and it has front-row seat to your spending habits
Google Pay is giving Gemini a peek inside your wallet
Google Pay using Gemini to help users understand their finances

Checking the transaction history on Google Pay can tell you where your money went, but going through the long list of merchant names and other payments can get tough to stay on top of. Or at least Google seems to think so, as it's bringing Gemini to Google Pay.

The company has launched Ask Google Pay, an opt-in conversational AI experience built directly into its payments app in India. Users can ask questions about their spending, request savings suggestions and learn about financial concepts. It will even share personalized offers based on their activity.

Read more
Gemini on Mac can now type what you say and act on what it sees
The Gemini app for macOS now offers system-wide dictation and an opt-in feature that lets it pull context from what's on screen to handle complex requests.
Gemini app macOS dictation featured

After rolling out Gemini Spark on macOS earlier this year, Google is now upgrading the Gemini app for Mac with two useful features that could change the way you get things done, whether that means ditching your current AI dictation app or letting Gemini act on whatever's on your screen.

One key press turns speech into clean text anywhere

Read more
Students are turning to AI chatbots instead of humans for college counseling
China's college counseling industry built a $160 million business on anxiety that free AI now threatens.
gaokao-ai-counseling

Every summer, roughly 10 million Chinese students face a brutal deadline. After taking the grueling Gaokao college entrance exam, they get just a few weeks to pick their universities and majors, a decision that can shape their entire career. Families used to pay hefty fees for expert guidance through this process. Now, free AI chatbots are quietly taking that business away.

How are AI chatbots replacing paid college consultants?

Read more