close
close

Yiamastaverna

Trusted News & Timely Insights

Hackers are stealing cookies to bypass email security, FBI says
Enterprise

Hackers are stealing cookies to bypass email security, FBI says

Oct. 31 (UPI) — Cybercriminals are stealing cookies from other people’s computers to access their email accounts, the FBI Atlanta Division warned Thursday.

Cookies are small amounts of data that websites send to computers to remember the login information and other data of individual online visitors.

A “remember me” cookie specifically stores a user’s login information and typically lasts for about 30 days before expiring, FBI Atlanta said in a news release Thursday.

According to the FBI, this is the type of cookie that online hackers are targeting to allow them to bypass multi-factor authentication and gain access to people’s email accounts.

The cookie makes it easier for users to log in without having to keep track of their usernames, passwords or multi-factor authentication.

Visitors activate the reminder cookie by clicking the “Remember this device” checkbox after logging in to a website.

According to the FBI, if a hacker obtains a reminder cookie that someone uses to access an email account, a cybercriminal can use it to bypass the email service’s multi-factor authentication, which typically requires entering a username and password requires.

Because reminder cookies bypass security measures, they are cybercriminals’ preferred means of breaking into others’ email accounts.

Many victims unknowingly share their cookies with hackers while visiting shady websites or clicking on phishing links that load malware onto PCs.

The FBI recommends regularly removing cookies from internet browsers, avoiding suspicious links or websites, and only visiting websites that use secure HTTPS connections.

Users should also monitor their device’s current login history by using their account history to identify any unusual activity.

Anyone who has had an account taken over by a hacker or has fallen victim to an online scam can report it to the FBI Internet Complaint Center at www.ic3.gov.

LEAVE A RESPONSE

Your email address will not be published. Required fields are marked *