• Login
  • Register
Nairametrics
  • Home
  • Exclusives
    • Financial Analysis
    • Corporate Stories
    • Interviews
    • Investigations
    • Metrics
    • Economy
    • Nairalytics
  • Markets
    • Currencies
    • Cryptos
    • Commodities
    • Equities
      • Company Results
      • Dividends
      • Stock Market
    • Fixed Income
    • Market Views
    • Securities
  • Sectors
    • Agriculture
    • Aviation
    • Company News
    • Consumer Goods
    • Corporate Updates
    • Corporate deals
    • Corporate Press Releases
    • Energy
    • Entertainment
    • Financial Services
    • Health
    • Hospitality & Travel
    • Manufacturing
    • Real Estate and Construction
    • Renewables & Sustainability
    • Tech News
  • Business News
    • Budget
    • Public Debt
    • Funds Management
    • Tax
  • Financial Literacy
    • Career tips
    • Personal Finance
  • Lifestyle
    • Billionaire Watch
    • Profiles
  • Opinions
    • Blurb
    • Op-Eds
    • Research Analysis
  • Recapitalization
    • Access Holdings Offer
    • Fidelity Bank Offer
    • GTCO Offer
    • Zenith Bank Offer
  • Home
  • Exclusives
    • Financial Analysis
    • Corporate Stories
    • Interviews
    • Investigations
    • Metrics
    • Economy
    • Nairalytics
  • Markets
    • Currencies
    • Cryptos
    • Commodities
    • Equities
      • Company Results
      • Dividends
      • Stock Market
    • Fixed Income
    • Market Views
    • Securities
  • Sectors
    • Agriculture
    • Aviation
    • Company News
    • Consumer Goods
    • Corporate Updates
    • Corporate deals
    • Corporate Press Releases
    • Energy
    • Entertainment
    • Financial Services
    • Health
    • Hospitality & Travel
    • Manufacturing
    • Real Estate and Construction
    • Renewables & Sustainability
    • Tech News
  • Business News
    • Budget
    • Public Debt
    • Funds Management
    • Tax
  • Financial Literacy
    • Career tips
    • Personal Finance
  • Lifestyle
    • Billionaire Watch
    • Profiles
  • Opinions
    • Blurb
    • Op-Eds
    • Research Analysis
  • Recapitalization
    • Access Holdings Offer
    • Fidelity Bank Offer
    • GTCO Offer
    • Zenith Bank Offer
Nairametrics
No Result
View All Result
Home Sectors

Hackers exploiting stolen cookies to attack corporate organisations – Report

Samson Akintaro by Samson Akintaro
August 18, 2022
in Sectors, Tech News
$100 million worth of NFTs have been stolen since July 2021
Share on FacebookShare on TwitterShare on Linkedin

Latest report from Sophos, a global leader in next-generation cybersecurity, has revealed that cybercriminals are increasingly exploiting stolen session cookies to bypass Multi-Factor Authentication (MFA) and gain access to corporate resources.

According to the report titled “Cookie Stealing: the new perimeter bypass”, in some cases, the cookie theft itself is a highly targeted attack, with adversaries scraping cookie data from compromised systems within a network and using legitimate executable to disguise the malicious activity.

Cookie theft occurs when third-party copies unencrypted session data from a website and uses it to impersonate the real user. Cookie theft most often occurs when a user accesses trusted sites over an unprotected or public Wi-Fi network.

RelatedStories

ransomware

Cyberattacks: Ransomware payments globally surge by 500% in 2023—Report

May 6, 2024
Cybercrime- a threat to AU’s agenda 2063

Why small businesses are becoming more vulnerable to cyberattacks – Report

March 12, 2024

Sophos said once the attackers obtain access to corporate web-based and cloud resources using the cookies, they can use them for further exploitation such as business email compromise, social engineering to gain additional system access, and even modification of data or source code repositories.

What they are saying

Commenting on the report, Principal Threat Researcher at Sophos, Sean Gallagher, said: “Over the past year, we’ve seen attackers increasingly turn to cookie theft to work around the growing adoption of MFA. Attackers are turning to new and improved versions of information stealing malware like Raccoon Stealer to simplify the process of obtaining authentication cookies, also known as access tokens. If attackers have session cookies, they can move freely around a network, impersonating legitimate users.”

“While historically we’ve seen bulk cookie theft, attackers are now taking a targeted and precise approach to cookie stealing. Because so much of the workplace has become web-based, there really is no end to the types of malicious activity attackers can carry out with stolen session cookies.

“They can tamper with cloud infrastructures, compromise business email, and convince other employees to download malware or even rewrite code for products. The only limitation is their own creativity. Complicating matters is that there is no easy fix. For example, services can shorten the lifespan of cookies, but that means users must re-authenticate more often, and, as attackers turn to legitimate applications to scrape cookies, companies need to combine malware detection with behavioural analysis,” Gallagher added.

Measures to prevent cookie theft

  • According to cybersecurity experts, one of the most basic ways you can prevent cookie theft and session hijacking is by checking URLs. More sure websites are using HTTPS to ensure that all of your session traffic is encrypted with SSL/TLS. Most websites these days use HTTPS encryption, but it’s best always to check. This is especially true when entering personal data.
  • You can check if a website uses HTTPS by looking at the URL at the top of your browser. Chrome, for example, displays a lock to the left of the URL when a website is using HTTPS.
  • Another privacy measure is to avoid logging onto free public Wi-Fi connections, especially those without password protection. Whenever you do log onto public Wi-Fi, always use these tips to keep your information safe on public WiFi.

Follow us for Breaking News and Market Intelligence.
Tags: CybercriminalsMFAMulti-Factor AuthenticationSophos
Samson Akintaro

Samson Akintaro

Samson Akintaro is a tech enthusiast and has over a decade experience covering and writing about the tech industry. He is currently the Tech Analyst at Nairametrics.

Related Posts

ransomware
Sectors

Cyberattacks: Ransomware payments globally surge by 500% in 2023—Report

May 6, 2024
Cybercrime- a threat to AU’s agenda 2063
Sectors

Why small businesses are becoming more vulnerable to cyberattacks – Report

March 12, 2024
Oluseyi Akindeinde, secures patent for blockchain-driven authentication system 
Corporate Updates

Oluseyi Akindeinde, secures patent for blockchain-driven authentication system 

September 6, 2023
ransomware, Sophos
Sectors

Sophos uncovers 4 ransomware groups using similar patterns to attack victims

August 14, 2023
Sophos uncovers multiple fake ChatGPT apps scamming users
Sectors

Sophos uncovers multiple fake ChatGPT apps scamming users

May 30, 2023
Sophos identifies 2 cyber fraud operations targeting social media users
Sectors

Sophos identifies 2 cyber fraud operations targeting social media users

February 13, 2023
Next Post
FG to review January 18 resumption date for schools across the country

FG asks students to sue ASUU over strike, insists lecturers won’t be paid during the period

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Emple
first bank
Zenth Bank









DUNS

Recent News

  • Lagos Govt begins demolition of shanties, unapproved buildings in Ikeja GRA 
  • TeKnowledge expands across Africa with new brand identity and AI-First expert services to accelerate enterprise transformation 
  • Nurses to account for 66% of Africa’s projected shortfall of 6.1 million health workers by 2030 – Ihekweazu 

Follow us on social media:

Recent News

Lagos Govt begins demolition of shanties, unapproved buildings in Ikeja GRA 

Lagos Govt begins demolition of shanties, unapproved buildings in Ikeja GRA 

May 10, 2025
TeKnowledge expands across Africa with new brand identity and AI-First expert services to accelerate enterprise transformation 

TeKnowledge expands across Africa with new brand identity and AI-First expert services to accelerate enterprise transformation 

May 10, 2025
  • iOS App
  • Android App
  • Contact Us
  • Home
  • Markets
  • Sectors
  • Economy
  • Business News
  • Financial Literacy
  • Disclaimer
  • Ads Disclaimer
  • Copyright Infringement

© 2025 Nairametrics

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Social Media Auto Publish Powered By : XYZScripts.com
No Result
View All Result
  • Home
  • Exclusives
    • Financial Analysis
    • Corporate Stories
    • Interviews
    • Investigations
    • Metrics
    • Economy
    • Nairalytics
  • Markets
    • Currencies
    • Cryptos
    • Commodities
    • Equities
      • Company Results
      • Dividends
      • Stock Market
    • Fixed Income
    • Market Views
    • Securities
  • Sectors
    • Agriculture
    • Aviation
    • Company News
    • Consumer Goods
    • Corporate Updates
    • Corporate deals
    • Corporate Press Releases
    • Energy
    • Entertainment
    • Financial Services
    • Health
    • Hospitality & Travel
    • Manufacturing
    • Real Estate and Construction
    • Renewables & Sustainability
    • Tech News
  • Business News
    • Budget
    • Public Debt
    • Funds Management
    • Tax
  • Financial Literacy
    • Career tips
    • Personal Finance
  • Lifestyle
    • Billionaire Watch
    • Profiles
  • Opinions
    • Blurb
    • Op-Eds
    • Research Analysis
  • Recapitalization
    • Access Holdings Offer
    • Fidelity Bank Offer
    • GTCO Offer
    • Zenith Bank Offer
  • Login
  • Sign Up

© 2025 Nairametrics