User:First Look Work
Chinese Hackers Find a Way to Bypass Two Factor Authentication 2020
Two-factor authentication requires users to verify themselves through two different authentications to better secure their accounts and privacy. It is a commonly used and recommended security protocol as it adds an additional layer of security, making it more difficult to compromise.
However, a group of hackers (APT20) has managed to bypass 2FA in attacks against industry targets.
These cyberattacks targeted multiple countries including Brazil, America, England, China, Spain, Italy, Germany, Portugal, Mexico, and France where the primary targets were healthcare, finance, insurance, and aviation companies.
In one of APT20’s attacks, the group successfully breached an unnamed company’s highly secured 2FA protocol and obtained software tokens to generate legitimate software license keys at will.
They used web servers in combination with VPNs as an initial point of entry to cover their tracks. They made use of already existing hardware tools on the target system instead of using customized malware as well. This is how the attack managed to stay undetected for a long time since using malware would’ve immediately flagged their activity.
However, while 2FA getting compromised is indeed concerning news, it is a highly sophisticated process that is relatively rare. Thus, this is no reason to stop using 2FA entirely especially since it is still one of the more robust security systems compared to the rest.
Content Disclaimer
Informasi ini disarikan dari Wikipedia dan disajikan kembali untuk tujuan edukasi. Konten tersedia di bawah lisensi CC BY-SA 3.0. Kami tidak bertanggung jawab atas ketidakakuratan data yang bersumber dari kontribusi publik tersebut.
- The information displayed on this website is sourced in part or in whole from Wikipedia and has been adapted for the purpose of restating it. We strive to provide accurate and relevant information, however:
- There is no guarantee of absolute accuracy. Wikipedia is an open, collaborative project that can be edited by anyone, so information is subject to change.
- It is not intended to constitute professional advice. The content displayed is for informational and educational purposes only. For important decisions (e.g., medical, legal, or financial), please consult a professional.
- Content copyright. Wikipedia is licensed under the Creative Commons Attribution-ShareAlike License (CC BY-SA). This means that content may be reused with appropriate attribution and shared under a similar license.
- Responsible use. Any risk arising from the use of information from this website is entirely the responsibility of the user.