Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
Four key questions about OpenAI vs Google—the high-stakes tech matchup of 2026

Four key questions about OpenAI vs Google—the high-stakes tech matchup of 2026

5 December 2025
Cloudflare Down—New Outage Takes Internet Down, Again

Cloudflare Down—New Outage Takes Internet Down, Again

5 December 2025
Treasury Secretary Bessent insists Trump’s tariff agenda is ‘permanent,’ saying the White House can recreate it even with a Supreme Court loss

Treasury Secretary Bessent insists Trump’s tariff agenda is ‘permanent,’ saying the White House can recreate it even with a Supreme Court loss

5 December 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » 2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks
Innovation

2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks

Press RoomBy Press Room19 March 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks

Whenever there is talk of hackers compromising services, be that in the form of Gmail lockout attacks, those that use infostealer malware, for ransomware threat actors brute-forcing passwords to firewalls and VPNs, you can bet your bottom dollar that the mitigation advice will include enabling two-factor authentication for all your accounts. But what if the hackers had a way around that? What if the hackers could bypass the 2FA code requirement and compromise your account anyway? Well, about that…

The Threat To 2FA Code Security Explained

Two-factor authentication is, without a shadow of a doubt, a necessity given the current threat landscape where infostealers rule supreme. If you are not using passkeys already, then your passwords are the weak spot that hackers will attack. Heck, most of the time, the hard work has already been done for them with infostealer logs compiled and sold on criminal marketplaces and dark web forums. All they then have to do is feed those passwords into a brute-force attack against accounts, and if, like 50% of users, you use the same credentials for multiple sites and services, well, you’re screwed. Unless that is, you have 2FA enabled, which acts as a nightclub doorman protecting the entrance to your account: if your 2FA code isn’t on the list, then you are not coming in. So far, so good. Now comes the bad news.

2FA bypass is a reality. Attackers don’t need your 2FA code to gain access to your account; what they use instead is a cookie. Yes, those things that we always think of in a privacy-related context as containing information about us that is fed back to the evil giants of technology. But not all cookies are the same, beyond counting important data. The important data contained within a session cookie already includes a flag that says 2FA has been completed, and all is fine and dandy. Threat actors will employ attacker-in-the-middle techniques to capture a session cookie after a victim has completed the initial password login and 2FA verification. That cookie is proof to your account that the session is authorized correctly. Critically, once a hacker has hold of such a session cookie, that authorized session can be re-run at their leisure without the need for your 2FA code at all.

Now that you understand how it works, you might not want to read SpyCloud’s newly published 2025 identity exposure report. According to the SpyCloud analysts, 17.3 billion session cookies were stolen across 2024 from malware-infected devices. As well as being valid authentication cookies, these included target URL’s to enable session hijacking, the report warned. “In the intricate web of cybercrime, stolen session cookies have become a powerful tool for attackers,” SpyCloud said, “allowing them to bypass authentication measures and hijack accounts.”

Mitigating 2FA Code Bypass Attacks

There are myriad ways that you can mitigate 2FA code bypass attacks, including the use of passkeys, which Google told me that internal research had shown to “substantially reduce the impact of phishing and other social engineering attacks.” Of course, you should also be aware of all the advice that has been given many times over about mitigating phishing attacks, as these are also used alongside malware infections to steal session cookies. Indeed, phishing is often how the infostealer malware gets installed in the first place, so be sure to stay alert.

2FA 2FA hack Cookie cookie theft Hacking 2FA MFA Multi-Factor Authentication Session Cookie SpyCloud two-factor authentication
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Cloudflare Down—New Outage Takes Internet Down, Again

Cloudflare Down—New Outage Takes Internet Down, Again

5 December 2025
Full Card, Time, Location And How To Watch

Full Card, Time, Location And How To Watch

5 December 2025
Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

5 December 2025
Chinese Challenger To Nvidia Mints A New Billionaire As Its Stock Soars Over 420% In Trading Debut

Chinese Challenger To Nvidia Mints A New Billionaire As Its Stock Soars Over 420% In Trading Debut

5 December 2025
Rotten Tomatoes Critics Crush ‘Five Nights At Freddy’s 2’

Rotten Tomatoes Critics Crush ‘Five Nights At Freddy’s 2’

5 December 2025
NYT ‘Pips’ Hints, Answers, And Walkthrough For Friday, December 5

NYT ‘Pips’ Hints, Answers, And Walkthrough For Friday, December 5

5 December 2025
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
John Summit went from working 9 a.m. to 9 p.m. in a ,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

John Summit went from working 9 a.m. to 9 p.m. in a $65,000 job to a multimillionaire DJ—‘I make more in one show than I would in my entire accounting career’

18 October 2025
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
Nintendo’s 98% staff retention rate means the average employee has been there 15 years

Nintendo’s 98% staff retention rate means the average employee has been there 15 years

5 December 20250 Views
Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

5 December 20250 Views
The office needs to be designed like an ‘experience,’ says Gensler’s Ray Yuen

The office needs to be designed like an ‘experience,’ says Gensler’s Ray Yuen

5 December 20250 Views
Chinese Challenger To Nvidia Mints A New Billionaire As Its Stock Soars Over 420% In Trading Debut

Chinese Challenger To Nvidia Mints A New Billionaire As Its Stock Soars Over 420% In Trading Debut

5 December 20250 Views
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
Four key questions about OpenAI vs Google—the high-stakes tech matchup of 2026

Four key questions about OpenAI vs Google—the high-stakes tech matchup of 2026

5 December 2025
Cloudflare Down—New Outage Takes Internet Down, Again

Cloudflare Down—New Outage Takes Internet Down, Again

5 December 2025
Treasury Secretary Bessent insists Trump’s tariff agenda is ‘permanent,’ saying the White House can recreate it even with a Supreme Court loss

Treasury Secretary Bessent insists Trump’s tariff agenda is ‘permanent,’ saying the White House can recreate it even with a Supreme Court loss

5 December 2025
Most Popular
Full Card, Time, Location And How To Watch

Full Card, Time, Location And How To Watch

5 December 20250 Views
Nintendo’s 98% staff retention rate means the average employee has been there 15 years

Nintendo’s 98% staff retention rate means the average employee has been there 15 years

5 December 20250 Views
Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

Watch Out For Media Rage-Baiting About The Topic Of AI For Mental Health

5 December 20250 Views
© 2025 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.