Close Menu
  • Business
    • Market Place
  • Devices & Gadgets
    • Buyers Guide
    • Trending
    • Social
  • Mobile & Telecoms
    • Broadband
  • Innovations
    • APPS
    • Start-ups
    • Software
    • AI ( artificial intelligence)
    • Auto-Tech
  • Health
    • Security
  • State
    • NCC
    • NiRA and .ng
    • NITDA
  • i-Sports
    • i-tertainment/Gaming
    • I-TV/Podcast
  • Reviews
    • Opinion
    • Special Report
    • Editorial and Analysis
  • Others
    • Events
    • Archive
    • Interviews
Facebook X (Twitter) Instagram
Latest
  • TD Africa Onboards Zinox Technologies, Expanding Its Basket of Global Brands
  • Highlights from the 10th Nigeria Innovation Summit
  • First Bank unveils its latest Digital Xperience Centre in Abuja
  • Yemisi Shyllon Museum of Art Presents Second Edition of Collecting Now Exhibition
  • E1 Lagos GP: Lagos Trends Worldwide After Hosting Africa’s Maiden Water Racing Event
  • TD Africa and IBM Spotlight Digital Innovation at GITEX Nigeria 2025
  • FBNQuest Merchant Bank bags “Great Place to Work” Certification
  • NCC in history – avoiding the psychic prison syndrome
Facebook X (Twitter) Instagram YouTube LinkedIn
IT NEWS NIGERIAIT NEWS NIGERIA
Subscribe Now
  • Business
    • Market Place
  • Devices & Gadgets
    • Buyers Guide
    • Trending
    • Social
  • Mobile & Telecoms
    • Broadband
  • Innovations
    • APPS
    • Start-ups
    • Software
    • AI ( artificial intelligence)
    • Auto-Tech
  • Health
    • Security
  • State
    • NCC
    • NiRA and .ng
    • NITDA
  • i-Sports
    • i-tertainment/Gaming
    • I-TV/Podcast
  • Reviews
    • Opinion
    • Special Report
    • Editorial and Analysis
  • Others
    • Events
    • Archive
    • Interviews
IT NEWS NIGERIAIT NEWS NIGERIA
Home»Security»Email attacks: Criminals bypass multi-factor authentication to hijack email accounts
Security

Email attacks: Criminals bypass multi-factor authentication to hijack email accounts

ITNEWSNIGERIABy ITNEWSNIGERIAAugust 6, 2020No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Share
Facebook Twitter LinkedIn Pinterest Email

Email attacks: Researchers at Abnormal Security have detected an increase in business email compromise attacks that successfully compromise email accounts despite the use of multi-factor authentication (MFA) and Conditional Access

Advertisement

IT News Nigeria

This is possible because legacy email protocols, including IMAP, SMTP, MAPI and POP, don’t support MFA. In addition many common applications — such as those used by mobile email clients (for example, iOS Mail for iOS 10 and older) — don’t support modern authentication.

A common pattern in account takeovers is that after being blocked by MFA an attacker will immediately switch to using a legacy application. In fact, most credential stuffing campaigns use legacy applications such as IMAP4 in order to ensure they don’t encounter difficulties from MFA at any point.

Abnormal has observed successful account takeovers where the attacker bypasses the policy by obscuring the name of the app they’re using. In one case, the attacker initially attempted to sign in using a legacy application but was blocked by Conditional Access. The attacker then waited several days before trying again, this time with the app information obscured, and successfully gained access to the account.

This demonstrates that while most account takeover attempts use brute force attacks and password spraying techniques, some attackers are more methodical and deliberate.

 For more visit Abnormal Security blog , Twitter staff hack

Photo Credit:Balefire/Shutterstock

  • betanews

Post Views: 253
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleTelecom Industry: Govt Will Protect All Interests – Pantami
Next Article July 2020’s Most Wanted Malware: Emotet Strikes Again After Five-Month Absence
ITNEWSNIGERIA

Related Posts

3 Mins Read

Sophos XDR Excels in MITRE ATT&CK Evaluations: Enterprise

December 17, 2024
3 Mins Read

Teresa Anania Joins Sophos as Chief Customer Officer

July 23, 2024
4 Mins Read

Financial Education: 8 Important Steps To Secure Your PalmPay Account

June 25, 2024
5 Mins Read

Trend Micro blocked 18 million email threats, 4million  malicious mobile apps targeted at Nigerian businesses

May 25, 2024
Leave A Reply Cancel Reply

About Us
IT NEWS NIGERIA (www.itnewsnigeria.ng) is an on-line platform aimed at enriching Nigeria and Africa content in the cyberspace.

We believe the future is online.
Popular Updates

Design Bootcamps vs Self-Taught, A product designer’s perspective

March 22, 2024

How to get N100,000 loan @3% at Zenith Bank and other services

November 12, 2020

Interview: From Start-ups to Big Brands: Growth Marketing Strategies that work by Oluwasekemi Akinbo

May 18, 2023

Subscribe to Updates

Get the latest tech news & updates from IT NEWS NIGERIA

Facebook X (Twitter) Instagram Pinterest YouTube LinkedIn
  • About Us
  • Privacy Policy
  • Terms of Service
  • Advertise With Us
  • Contact Us
© 2025 IT NEWS NIGERIA.

Type above and press Enter to search. Press Esc to cancel.

Signup to our Newsletter