Hackers can bypass FIDO MFA keys, putting your accounts at risk – here’s what we know




  • A phishing campaign spotted trying to work around FIDO keys
  • The “cross-device sign in” feature triggers a QR code
  • Crooks can relay the QR code to bypass MFA and log in

Hackers have found a way to steal login credentials even for accounts protected with Fast IDentity Online (FIDO) physical keys. It revolves around a fallback created in these multi-factor authentication (MFA) solutions, and only works in certain scenarios.

FIDO keys are small physical, or software authenticators, that use cryptographic technology to securely log users into websites and apps. They serve as a multi-factor authenticator, preventing cybercriminals who have already obtained login credentials from accessing the targeted accounts.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *