Hackers have found a way to overcome two-factor authentication

NGUYỄN ĐĂNG |

According to AFP, citing cybersecurity experts, hackers have developed a set of scams that can overcome two-factor authentication.

2-factor authentication has become a standard security feature in cybersecurity. This form requires users to verify their identity with a second authentication step, usually an OTP sent via text message, email or authentication application.

This additional layer of security is intended to protect users' accounts even if their passwords are stolen

The use of 2FA is recommended by cybersecurity experts to protect access to users' most sensitive accounts from emails, social media accounts, shopping applications, banks or e-wallets.

This solution, previously considered an invincible barrier to hackers, is being sabotaged by a scam tool called Astaroth. Cybersecurity experts at SlashNext were the first to discover the new tool, which is capable of overcoming two-factor authentication on Google, Microsoft and Yahoo accounts.

To overcome two-factor authentication, hackers send a scam link to users, pointing them to a fake login page that completely imitates the real interface of the target platform. When users enter their login information and secret code, this information will immediately be taken over by cybercriminals and their accounts will be stolen.

What makes Astaroth especially dangerous is its ability to block two-factor authentication in real time. According to SlashNext, the complete product set is sold on Dark Web (the hidden part of the Internet that is not indexed by regular search engines, where transactions often take place anonymously) for 2,000 USD.

To protect themselves from this type of attack, according to cybersecurity experts, as usual, users must be extremely vigilant and avoid clicking on suspicious links from unidentified senders.

Users should also use other, or even safer authentication methods, such as passkey (a security solution that does not require a traditional password), using fingerprints, facial recognition, or authentication codes stored on the device. This can be done with solutions from Apple, Google and Microsoft.

NGUYỄN ĐĂNG
RELATED NEWS

Images of iPhone 17 Pro Max revealed

|

After the iPhone 16e was announced, attention is now focusing on the upcoming iPhone 17 series.

MacBook Air M4 may be launched in March

|

New updates say Apple is likely to launch the MacBook Air M4 in March.

The humid season haunts cheap boarding houses in Hanoi

|

Hanoi - Prolonged humidity has caused many cheap boarding houses in Hanoi to be flooded and walls moldy. Poor workers and people with underlying diseases face an increased risk of illness.

Consumers are still hesitant to use biofuel

|

In some localities, consumers are still hesitant to use biofuel due to the lack of regular communication.

Pensions and social insurance allowances for February and March: Tens of trillions of VND have reached beneficiaries

|

According to Vietnam Social Security, 44,730 billion VND of pensions and social insurance allowances for February and March 2026 have been paid to beneficiaries in the February 2026 payment period.

Converting IELTS scores into universities in 2026

|

The IELTS conversion table when applying to universities in 2026 is continuously updated by Lao Dong for candidates and parents to follow.

Russia hands over 200 first Storm reconnaissance UAVs to the military

|

The first batch of more than 200 Storm unmanned aerial vehicles (UAVs) has been handed over by the manufacturer to the Russian army.

Long Thanh airport is about to open, Ho Chi Minh City urgently completes connectivity

|

Ho Chi Minh City - Long Thanh Airport will be operational from mid-2026. Ho Chi Minh City directs acceleration of connecting transport projects to avoid congestion when the airport comes into operation.

Images of iPhone 17 Pro Max revealed

Anh Vũ |

After the iPhone 16e was announced, attention is now focusing on the upcoming iPhone 17 series.

MacBook Air M4 may be launched in March

QUANG MINH (theo engadget) |

New updates say Apple is likely to launch the MacBook Air M4 in March.

Cảnh báo về các hình thức tấn công giả mạo để vượt xác thực 2 yếu tố

NGUYỄN ĐĂNG |

Các chuyên gia an ninh mạng của Kaspersky đã phát hiện ra các hình thức tấn công giả mạo (phishing) được tội phạm mạng sử dụng để vượt xác thực 2 yếu tố (2FA) – vốn là một biện pháp bảo mật quan trọng được thiết kế để bảo vệ tài khoản trực tuyến.