Multi-factor authentication (MFA) is a great way to add an extra layer of security to your login portals. However, clever cybercriminals may use a new method to bypass MFA and compromise your accounts. While cybercriminals haven't used this method in a real-world scam yet, researchers believe this scam could occur in the future.
In this scam, the cybercriminals use software called noVNC and a simple phishing link to bypass your MFA. The cybercriminals send you a phishing email that tells you to take urgent action and log in to your social media account or a similar website. If you click the link, you’ll be redirected to a fake login page that looks similar to the targeted website. However, this fake login page is actually on the cybercriminals’ server.
If you enter your credentials and MFA passcode on this page, the cybercriminals will be able to log in to your account from their own devices. Then, the cybercriminals can store your credentials for future access to your account.
Follow the tips below to stay safe from these types of scams:
The Security First IT Team SecurityFirstIT.com |