Read on app Read on app
✕
Prayer Times
  • Morocco
  • Lifestyle
  • Western Sahara
  • Login
Morocco World News
  • News
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport
No Result
View All Result
Morocco World News
  • News
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport
No Result
View All Result
Morocco World News

Home » Headlines » Hackers Have Found a New Way Around Two-Factor Authentication

Hackers Have Found a New Way Around Two-Factor Authentication

Two-factor authentication still helps, but it’s no longer a perfect shield.

Oumaima Moho AmerbyOumaima Moho Amer
Dec, 15, 2025
0 0
A A
Two-factor authentication still helps, but it’s no longer a perfect shield.

Two-factor authentication still helps, but it’s no longer a perfect shield.

Mohammedia – Two-factor authentication has long been sold as a strong safety net for online accounts. The idea is simple: even if someone steals your password, they still can’t log in without a second code sent to your phone or generated by an app.

For many users, that extra step feels like a guarantee of safety. But cybersecurity researchers are now warning that hackers have found a way around it — and the trick is almost impossible to notice.

The method doesn’t rely on guessing codes or breaking into phones. Instead, attackers are targeting something most users never think about: session cookies.

These are small files saved by your browser after you log in. They tell a website, “Yes, this person is already verified.” If a hacker gets hold of that cookie, they don’t need your password or your two-factor code anymore.

Security researchers say this type of attack is becoming more common, thanks to a phishing tool called Evilginx. It allows hackers to quietly slip between a user and the real website they are trying to access, without raising suspicion.

How the attack works without raising alarms

The attack usually starts with a link. It can arrive by email, text message, or social media, and it leads to what looks like a normal login page for a bank, email service, or social network. The design is familiar, the address looks convincing, and the browser even shows the HTTPS lock icon.

When the user enters their username and password, the fake page sends that information to the real website in real time. The legitimate site then asks for the second authentication code. The user receives the code, enters it, and successfully logs in — or so it seems.

Behind the scenes, the hacker’s server captures the session cookie created at that moment. This cookie proves to the website that the user has already passed all security checks. The attacker copies it and sends the user on their way, fully logged in and unaware anything is wrong.

With that stolen cookie, hackers can open the account in their own browser as if they were the owner. They don’t need the password again. They don’t need a new code.

They can read emails, change account settings, access personal data, or even move money, depending on the service. This access lasts until the session expires or is manually cut off.

What makes this attack especially dangerous is how invisible it is. Nothing looks broken. No warning appears. Many victims only find out days later, after noticing strange activity or getting an alert from their bank or email provider.

Experts say there are ways to reduce the risk. Users should be extremely cautious with unexpected links and always double-check website addresses before logging in.

More secure options, like physical security keys, offer better protection against phishing. If there’s any suspicion of a breach, logging out of all active sessions can instantly block attackers by invalidating stolen cookies.

Online security has become a moving target — and hackers are learning how to slip through the gaps without being seen.

Read also: Cybersecurity in 2026: The 10 Biggest Digital Threats on the Horizon

Tags: Cybersecurityhackersphishing
TweetShareShareSendShareScan

Recent News

Tangier Election Fraud Case Enters Detailed Questioning Phase

Tangier Election Fraud Case Enters Detailed Questioning Phase

October 8, 2026
FA Fines Everton’s Martin Sherif Over 61 Gambling Breaches

FA Fines Everton’s Martin Sherif Over 61 Gambling Breaches

October 8, 2026
AS FAR opened their 2026-27 Botola Pro campaign with a 1-0 victory over Widad Temara on Thursday at the Prince Moulay Abdellah Sports

AS FAR Beat Widad Temara 1-0 in First Botola Match of Season

October 8, 2026
FiveNines Group Leads Development of 20MW AI Data Center Near Casablanca

FiveNines Group Leads Development of 20MW AI Data Center Near Casablanca

October 8, 2026
Confederation of African Football (CAF) President Patrice Motsepe has announced that all 54 African national football associations

CAF and 54 African Federations Back Infantino for FIFA Re-Election

October 8, 2026

USEFUL LINKS

  • About
  • Privacy Policy
  • Contact
  • Careers
  • Terms Of Use
  • Cookies Policy

TOPICS

  • Mawazine 2025
  • Environment
  • Politics
  • Lifestyle
  • Sports
  • Western Sahara

REGIONS

  • International
  • Maghreb
  • Middle East
  • Africa

Download our App


Download the Morocco World News app on Google Play for Android

Download the Morocco World News app on the Apple App Store for iPhone and iPad

Copyright 2026 Morocco World News. All rights reserved. Morocco World News is not responsible for the content of external sites.
Read about our approach to external linking.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
  • Login
No Result
View All Result
  • News
  • Culture
  • Politics
  • Society
  • Economy
  • Opinion
  • Education
  • Sustainability
  • Tech
  • Sport

Useful Links

  • Prayer Times

Useful Links:

  • Prayer Times

All Right Reserved © 2026 Morocco World News .

Contact us
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?