Dual Factor Authentication Can Be Hacked By Phishing
Privacy, Cyber & AI Decoded Alert | 2 min read
May 16, 2018
Download or read the complete alert here: Cyber Alert - Dual Factor Authentication Can Be Hacked By Phishing (PDF)
Risk Management Question: Dual factor authentication greatly increases your online security, but it is no panacea. Dual factor authentication can be compromised through social engineering and phishing exploits. What can law firms and their employees do to identify and avoid phishing emails attempts to defeat the protection provided by dual factor authentication?
The Issue: Dual factor authentication increases online security because it adds an additional step or layer of protection when logging in to gain account access. However, accounts protected by dual factor authentication can still be hacked via phishing emails. Included below is a link to a video from Kevin Mitnick, a computer security consultant, showing how an account protected by dual factor authentication can be compromised. It's called "session cookie hijacking."
The video demonstrates how an attack can occur with a phishing email that appears to be sent by a LinkedIn member asking the victim to connect. In the video, Mr. Mitnick notes that while the email looks legit, if you carefully review it, you will find that the return email address is incorrect. When the victim clicks on the "interested" button, malware is launched onto the victim's computer. The victim is taken to the real LinkedIn site where login information is required to complete the process, which includes LinkedIn sending a text message (the dual factor) with the access code to the victim's phone. However, the malware is capturing the victim's email address, password and session cookie, which will allow the hacker to later access the victim's account directly and bypass the dual factor authentication portion of the sign-in process. While the video uses LinkedIn, the same attack can be made to any online account.
When you watch the video you may be surprised to see how easy it is to hack dual factor authentication if you are phished:
This is not meant to suggest that lawyers shouldn't use dual factor authentication – it should be used whenever it's offered for remote access to any online account. However, even this protection can be hacked if you are not careful with how you handle email attachments and links. Always think before you click.
Risk Management Solution: Remember these three essential phishing rules:
- Never click on a link or an attachment from someone you don't know;
- Never click on a link or an attachment you were not expecting to receive, even if you know the sender. Call the person first to confirm that person (rather than a hacker) sent you the email before you click on anything; and
- Finally, if you forget the first two rules and click on a link or an attachment and either a zip file or dialog box is presented which asks you to supply additional information or a password, enable a later software version, or open the zip file, stop immediately and close out. Then call your firm's IT department to have a scan run on your computer.
Another way to mitigate this exploit is to avoid using the link provided in the email and instead go to the site directly. This may not be foolproof, but it helps reduce session cookie hijacking.
This alert has been prepared by Hinshaw & Culbertson LLP to provide information on recent legal developments of interest to our readers. It is not intended to provide legal advice for a specific situation or to create an attorney-client relationship.
Related People
Related Capabilities
Featured Insights

In The News
Jul 16, 2026
Jennifer Driscoll Anticipates Epic Battle Between “Titans of the Antitrust Bar”

Press Release
Jul 15, 2026
Two Hinshaw Partners Recognized in Minnesota Monthly's 2026 Top Lawyers in Minnesota

Event
July 13-15, 2026
Hinshaw Proudly Sponsors 2026 Lavender Law Conference and Career Fair

Webinar
Jul 14, 2026
Scott Seaman Presents on Horizontal vs. Vertical Exhaustion of Insurance

Healthcare Alert
Jul 8, 2026
A New Era of Compliance Standards for California DSOs and MSOs After the Aspen Dental Settlement

Insights for Insurers Alert
Jul 7, 2026
What Insurers Need to Know About California’s FAIR Plan Assessment Recoupment Guidance

In The News
Jul 6, 2026
Francesco Palanda’s Practical Guide for Mitigating AI-Related Business Interruption Risk

Lawyers' Lawyer Newsletter
Jun 29, 2026
Beyond Malpractice: The Rising Threat of Privacy and Statutory Claims Against Lawyers




