A Hidden Threat: FBI Warns of Cookie Exploit Bypassing Multifactor Authentication Security
The FBI’s Atlanta Division has warned that cybercriminals are bypassing multifactor authentication (MFA) by stealing “Remember-Me cookies” from victims’ computers. These cookies, which allow users to stay logged in without re-entering credentials or MFA, are commonly used when users select the “Remember this device” option. Once obtained, hackers can exploit these cookies to access victims’ email accounts without needing their usernames, passwords, or MFA codes. Cybercriminals often acquire these cookies through phishing links or malicious websites that install malware, which collects session data. To combat this threat, the FBI advises users to regularly clear browser cookies, avoid using the “Remember Me” option on sensitive accounts, only visit secure websites, and avoid suspicious links.