Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 299, Issue 2IT NewsMFA

Reddit Hack Shows Limits of MFA, Strengths of Security Training

DARKReading, February 10th, 2023

A tailored spear-phishing attack successfully convinced a Reddit employee to hand over their credentials and their one-time password, but soon after, the same worker notified security.

The latest hack of a well-known company highlights that attackers are increasingly finding ways around multifactor authentication (MFA) schemes - so employees continue to be an important last line of defense.

On Jan. 9, Reddit notified its users that a threat actor had successfully convinced an employee to click on a link in an email sent out as part of a spearphishing attack, which led to "a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens."

more →  ·  More from MFA →