Close Menu
Alpha Leaders
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
What's On
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

21 May 2026
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Alpha Leaders
newsletter
  • Home
  • News
  • Leadership
  • Entrepreneurs
  • Business
  • Living
  • Innovation
  • More
    • Money & Finance
    • Web Stories
    • Global
    • Press Release
Alpha Leaders
Home » 2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks
Innovation

2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks

Press RoomBy Press Room19 March 20253 Mins Read
Facebook Twitter Copy Link Pinterest LinkedIn Tumblr Email WhatsApp
2FA Code Warning As Hackers Steal 17 Billion Cookies To Use In Attacks

Whenever there is talk of hackers compromising services, be that in the form of Gmail lockout attacks, those that use infostealer malware, for ransomware threat actors brute-forcing passwords to firewalls and VPNs, you can bet your bottom dollar that the mitigation advice will include enabling two-factor authentication for all your accounts. But what if the hackers had a way around that? What if the hackers could bypass the 2FA code requirement and compromise your account anyway? Well, about that…

The Threat To 2FA Code Security Explained

Two-factor authentication is, without a shadow of a doubt, a necessity given the current threat landscape where infostealers rule supreme. If you are not using passkeys already, then your passwords are the weak spot that hackers will attack. Heck, most of the time, the hard work has already been done for them with infostealer logs compiled and sold on criminal marketplaces and dark web forums. All they then have to do is feed those passwords into a brute-force attack against accounts, and if, like 50% of users, you use the same credentials for multiple sites and services, well, you’re screwed. Unless that is, you have 2FA enabled, which acts as a nightclub doorman protecting the entrance to your account: if your 2FA code isn’t on the list, then you are not coming in. So far, so good. Now comes the bad news.

2FA bypass is a reality. Attackers don’t need your 2FA code to gain access to your account; what they use instead is a cookie. Yes, those things that we always think of in a privacy-related context as containing information about us that is fed back to the evil giants of technology. But not all cookies are the same, beyond counting important data. The important data contained within a session cookie already includes a flag that says 2FA has been completed, and all is fine and dandy. Threat actors will employ attacker-in-the-middle techniques to capture a session cookie after a victim has completed the initial password login and 2FA verification. That cookie is proof to your account that the session is authorized correctly. Critically, once a hacker has hold of such a session cookie, that authorized session can be re-run at their leisure without the need for your 2FA code at all.

Now that you understand how it works, you might not want to read SpyCloud’s newly published 2025 identity exposure report. According to the SpyCloud analysts, 17.3 billion session cookies were stolen across 2024 from malware-infected devices. As well as being valid authentication cookies, these included target URL’s to enable session hijacking, the report warned. “In the intricate web of cybercrime, stolen session cookies have become a powerful tool for attackers,” SpyCloud said, “allowing them to bypass authentication measures and hijack accounts.”

Mitigating 2FA Code Bypass Attacks

There are myriad ways that you can mitigate 2FA code bypass attacks, including the use of passkeys, which Google told me that internal research had shown to “substantially reduce the impact of phishing and other social engineering attacks.” Of course, you should also be aware of all the advice that has been given many times over about mitigating phishing attacks, as these are also used alongside malware infections to steal session cookies. Indeed, phishing is often how the infostealer malware gets installed in the first place, so be sure to stay alert.

2FA 2FA hack Cookie cookie theft Hacking 2FA MFA Multi-Factor Authentication Session Cookie SpyCloud two-factor authentication
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link

Related Articles

Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 2026
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 2026
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 2026
​How AI Is Changing The Economics Of Integration

​How AI Is Changing The Economics Of Integration

21 May 2026
Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

Airbnb CEO Brian Chesky Called Chinese AI Fast And Cheap. Now, Congress Wants Answers

21 May 2026
Don't Miss
Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

Unwrap Christmas Sustainably: How To Handle Gifts You Don’t Want

By Press Room27 December 2024

Every year, millions of people unwrap Christmas gifts that they do not love, need, or…

Exclusive: DeFi platform Azura launches after raising .9 million from Initialized

Exclusive: DeFi platform Azura launches after raising $6.9 million from Initialized

22 October 2024
Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

Walmart dominated, while Target spiraled: the winners and losers of retail in 2024

30 December 2024
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Latest Articles
MacKenzie Scott snubbed from top donors list despite  billion philanthropy

MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

21 May 20262 Views
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views
‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

‘We do not want humans to have the same fate as dinosaurs’: SpaceX IPO reads like Hollywood fantasy version of the future

21 May 20260 Views
2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

2 Tell-Tale Signs Of ‘Fake Love’ In A Relationship, By A Psychologist

21 May 20262 Views

Recent Posts

  • McKinsey partner says up to 50% of work hours could be transformed within the next 5 years
  • Securing The Internet’s Humanity
  • Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’
  • Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do
  • MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

Recent Comments

No comments to show.
About Us
About Us

Alpha Leaders is your one-stop website for the latest Entrepreneurs and Leaders news and updates, follow us now to get the news that matters to you.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

McKinsey partner says up to 50% of work hours could be transformed within the next 5 years

21 May 2026
Securing The Internet’s Humanity

Securing The Internet’s Humanity

21 May 2026
Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

Allbirds’ 600% stock surge says a lot about how ‘AI washing’ became the new ‘greenwashing’

21 May 2026
Most Popular
Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

Microsoft Is Scrapping SMS 2FA Codes—What You Need To Do

21 May 20261 Views
MacKenzie Scott snubbed from top donors list despite  billion philanthropy

MacKenzie Scott snubbed from top donors list despite $7 billion philanthropy

21 May 20262 Views
Why Complexity Is The Insider Threat Hiding In Plain Sight

Why Complexity Is The Insider Threat Hiding In Plain Sight

21 May 20261 Views

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • March 2022
  • January 2021
  • March 2020
  • January 2020

Categories

  • Blog
  • Business
  • Entrepreneurs
  • Global
  • Innovation
  • Leadership
  • Living
  • Money & Finance
  • News
  • Press Release
© 2026 Alpha Leaders. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.