This is NOT Fraud Advice--Cookies

This is NOT Fraud Advice--Cookies

Hello, everyone! Welcome back to Not Fraud Advice, where we expose how internet fraudsters operate, all in the name of keeping you informed (and maybe just a bit paranoid).

There is a new cookie monster in the world of digital fraud. The FBI announced last week that cybercriminals have used "remember me" cookies to bypass MFA checks and take over your account.

What’s a “Remember Me” Cookie?

Imagine logging into your email or favorite shopping site and seeing that helpful "Remember Me" checkbox. You click it, thinking you're saving a few seconds of future logins. But here's the catch: the "Remember Me" button generates a "cookie" that stays in your browser for up to 30 days, keeping your session active without re-entering your password or MFA code.

Here's where it gets dicey: cybercriminals are laser-focused on stealing these cookies because if they can grab one, they don't need your username, password, or even that second layer of protection provided by MFA. All they need is a single click, and they're in, masquerading as you.

How They Do It: The Phishing Hook

Cybercriminals can snag cookies in several ways, but one of their favorite tactics is the old bait-and-switch. They lure unsuspecting users into visiting shady websites or clicking phishing links that download malicious software onto the computer. Once that malware is installed, it's just a matter of time before it scoops up your cookies, handing the fraudster a skeleton key to your accounts.

How to Stay Safe: It’s Not All Doom and Gloom

Before you go clearing all your cookies and refusing every "Remember Me" checkbox, here are a few practical tips to make sure you aren't handing over your data to cookie crooks:

  1. Clear Your Cookies Regularly: It's a pain, but wiping your browser clean every so often helps to reset those sessions and reduce the chances of an attacker getting in.
  2. Think Twice Before Clicking "Remember Me": I know it's convenient, but skipping this option is safer for any particularly sensitive account.
  3. Only Click on Trusted Links: Phishing attacks often start with a fake link. If it looks suspicious, don't click it. Check if the site is secure (look for "HTTPS"), especially when logging into sensitive accounts.
  4. Monitor Your Login History: Most accounts show recent logins under your settings. Keep an eye out for any unfamiliar devices or locations.
  5. Passkeys: You all know that passkeys are one of my favorite topics. Footprint is fully committed to passkeys; we believe they will replace passwords in the future. Passkeys are unphishable credentials that can protect you and your online identity.

The cookie-stealing trend is just one example of how attackers innovate to get around the protections we rely on. If you're worried about the gaps in your security, it might be time to look into more sophisticated identity verification tools. We know a team that's good at this sort of thing.

BTW - do not forget to register for our webinar next week! We will be chatting through the evolving fraud landscape: https://us06web.zoom.us/webinar/register/7217307474143/WN_-qd6UEALT3SBFBuf2XGcMQ

Simsan Mallick

IT Consultant | Expert in Software Outsourcing, IT Staff Augmentation, and Offshore Office Expansion | Delivering High-Quality Web & Mobile Application Solutions

3 个月

The focus on evolving fraud tactics, like cookie stealing, is critical for staying ahead. What preventive measures do you recommend for businesses to tackle these advanced threats?

回复
Pushkar P.

Simplifying payments and fintech for businesses ( because Who has time for a 20-page report? ) | Strategic Advisor | Angel Investor

3 个月

Crazy how cybercriminals are getting more creative with cookies! Definitely tuning in for that webinar, sounds like a game changer. Eli Wachs ??

要查看或添加评论,请登录

Eli Wachs ??的更多文章

  • This is NOT Fraud Advice--SMS Blasters

    This is NOT Fraud Advice--SMS Blasters

    Happy Friday - hope you all have gotten to enjoy some warmer weather across the States this week. The Footprint team is…

    1 条评论
  • This is NOT Fraud Advice: But the FBI Thinks this is a Scam edition

    This is NOT Fraud Advice: But the FBI Thinks this is a Scam edition

    The FBI is sounding the alarm: a massive, AI-driven scam wave is hitting iPhone and Android users alike. And this isn’t…

    2 条评论
  • This is NOT Fraud Advice: Zelle Cracks Down, Nubank Leads the Way

    This is NOT Fraud Advice: Zelle Cracks Down, Nubank Leads the Way

    Chase Launches New Zelle's Guardrails: No More Social Media Payments Zelle, the popular peer-to-peer payment service…

    2 条评论
  • This is NOT Fraud Advice--Tenant Screening

    This is NOT Fraud Advice--Tenant Screening

    We’re back, explaining (but definitely not advising) how people commit fraud. TIL that Wisconsin has a lot of fraud.

    2 条评论
  • This is NOT Fraud Advice: The Rise of Automated CPN Fraud

    This is NOT Fraud Advice: The Rise of Automated CPN Fraud

    The fraud world has always had its fair share of innovation, but the latest development—software that automates…

    3 条评论
  • This is NOT Fraud Advice--Rental Listing Scams

    This is NOT Fraud Advice--Rental Listing Scams

    Hope everyone is staying warm this week. Today we are going to chat through rental listing scams.

  • This is NOT Fraud Advice--Brad Pitt

    This is NOT Fraud Advice--Brad Pitt

    This week, a French woman named Anne found herself at the center of an online whirlwind after revealing she had been…

    4 条评论
  • This is NOT Fraud Advice--Medicaid

    This is NOT Fraud Advice--Medicaid

    Welcome Back to “Not Fraud Advice,” Where the Playbook of Fraudsters Gets Exposed This week, we’re breaking down one of…

    1 条评论
  • This is NOT Fraud Advice--Cops

    This is NOT Fraud Advice--Cops

    Hello, everyone! The other week, we hosted a webinar with our head of risk, Dave Argoff. Dave has over a decade of…

  • This is NOT Fraud Advice--Deep Fakes

    This is NOT Fraud Advice--Deep Fakes

    Happy Friday, everyone. If you haven’t seen it yet, last week FinCEN issued an alert that should make anyone in fintech…

    2 条评论

社区洞察

其他会员也浏览了