Dual Factor Authentication Can Be Hacked By Phishing
Privacy, Cyber & AI Decoded Alert | 2 min read
May 16, 2018
Download or read the complete alert here: Cyber Alert - Dual Factor Authentication Can Be Hacked By Phishing (PDF)
Risk Management Question: Dual factor authentication greatly increases your online security, but it is no panacea. Dual factor authentication can be compromised through social engineering and phishing exploits. What can law firms and their employees do to identify and avoid phishing emails attempts to defeat the protection provided by dual factor authentication?
The Issue: Dual factor authentication increases online security because it adds an additional step or layer of protection when logging in to gain account access. However, accounts protected by dual factor authentication can still be hacked via phishing emails. Included below is a link to a video from Kevin Mitnick, a computer security consultant, showing how an account protected by dual factor authentication can be compromised. It's called "session cookie hijacking."
The video demonstrates how an attack can occur with a phishing email that appears to be sent by a LinkedIn member asking the victim to connect. In the video, Mr. Mitnick notes that while the email looks legit, if you carefully review it, you will find that the return email address is incorrect. When the victim clicks on the "interested" button, malware is launched onto the victim's computer. The victim is taken to the real LinkedIn site where login information is required to complete the process, which includes LinkedIn sending a text message (the dual factor) with the access code to the victim's phone. However, the malware is capturing the victim's email address, password and session cookie, which will allow the hacker to later access the victim's account directly and bypass the dual factor authentication portion of the sign-in process. While the video uses LinkedIn, the same attack can be made to any online account.
When you watch the video you may be surprised to see how easy it is to hack dual factor authentication if you are phished:
This is not meant to suggest that lawyers shouldn't use dual factor authentication – it should be used whenever it's offered for remote access to any online account. However, even this protection can be hacked if you are not careful with how you handle email attachments and links. Always think before you click.
Risk Management Solution: Remember these three essential phishing rules:
- Never click on a link or an attachment from someone you don't know;
- Never click on a link or an attachment you were not expecting to receive, even if you know the sender. Call the person first to confirm that person (rather than a hacker) sent you the email before you click on anything; and
- Finally, if you forget the first two rules and click on a link or an attachment and either a zip file or dialog box is presented which asks you to supply additional information or a password, enable a later software version, or open the zip file, stop immediately and close out. Then call your firm's IT department to have a scan run on your computer.
Another way to mitigate this exploit is to avoid using the link provided in the email and instead go to the site directly. This may not be foolproof, but it helps reduce session cookie hijacking.
This alert has been prepared by Hinshaw & Culbertson LLP to provide information on recent legal developments of interest to our readers. It is not intended to provide legal advice for a specific situation or to create an attorney-client relationship.
Related People
Related Capabilities
Featured Insights

Press Release
May 20, 2026
Hinshaw Releases America 250 Book Exploring Insurance's Role in Building the United States

Consumer Crossroads: Where Financial Services and Litigation Intersect
May 19, 2026
OCC's Final Escrow-Interest Preemption Rules Bolster the Second Circuit’s Cantero Decision

Webinar
May 19, 2026
Scott Seaman Speaks on Making Decisions in Difficult Risk Environments

Consumer Crossroads: Where Financial Services and Litigation Intersect
May 14, 2026
Key Takeaways from the 2026 MBA Legal Issues and Regulatory Compliance Conference

Consumer Crossroads: Where Financial Services and Litigation Intersect
May 14, 2026
SCOTUS Confirms: Federal Courts Retain Power to Affirm or Vacate an Arbitration Decision

In The News
May 13, 2026
Hinshaw Contributes Chapters to “Wrongful-Death and Survival Actions” IICLE Handbook

In The News
May 12, 2026
Hinshaw GC Steve Puiszis Discusses Protecting Attorney-Client Privilege in an AI Age

Event
May 12-13, 2026
Mitchel Chargo Speaks on the Rapidly Evolving Cannabis Industry

Consumer Crossroads: Where Financial Services and Litigation Intersect
May 11, 2026
Tennessee Reaches Settlement with Mariner in Multistate UDAAP Enforcement Action

Press Release
May 11, 2026
Ali Degan Elected to the Fellows of the American Bar Foundation

Press Release
May 11, 2026
John Weedon Re-Elected to the Jacksonville Bar Association’s Board of Governors in 2026


