One-time codes used to hack corporate accounts

One-time codes used to hack corporate accounts

Security firm Proofpoint has discovered that hackers have found a clever way to bypass multi-factor authentication (MFA) and thereby get their hands on accounts belonging to corporate users.

In a nutshell, the hackers are using one-time codes from OAuth 2.0, an open standard that is supposed to be used to authenticate smart TVs and the like.

Typically, the scammers pretend that a particular device needs a one-time code and get users to type the code into Microsoft’s authentication link. Once users do so, the hackers gain full access to their Microsoft 365 accounts with all their content.

Both Russian and Chinese hackers have used this method, so there’s every reason for companies to tighten up their procedures.

For additional reporting, see Hackers exploit Microsoft OAuth device codes to hijack enterprise accounts.

​The original article found on Amazon has stopped 1,800 job applications from North Korean agents | CSO Online Read More