Email Security Threats: Beware The Session Cookies

By: Ben Fielding | Estimated Reading Time: 3 minutes

Online security is a constant concern for businesses, and protecting against email security threats is essential for maintaining data privacy and trust. Yet, a recent FBI alert has shed light on a growing threat: cybercriminals gaining access to email accounts. Even those protected by multi-factor authentication (MFA). This latest security challenge involves a sneaky tactic called session or “remember me” cookie theft.

What Is Session Cookie Theft?

When you log into a website, session cookies are created to remember your login information, allowing you to bypass re-entering your credentials every time you visit. This is the “remember me” function used by Gmail, Outlook, and most web-based accounts. While convenient, these session cookies are increasingly targeted by cybercriminals who gain access to them through malicious links or phishing attacks. Once they have your session cookie, attackers can bypass MFA and access your account without needing your password or verification code.

How Cybercriminals Exploit Session Cookies

Cybercriminals launch attacks by luring users into clicking on phishing links that download malware to their devices. This malware then steals the session cookies from the user’s browser, allowing attackers to access the account as if they were the legitimate user. This type of attack is particularly dangerous because, even if a user has MFA enabled, it can still be bypassed.

Email Platforms at Risk

The FBI warns that this threat affects all major email platforms that offer web logins, such as Gmail, Outlook, Yahoo, and AOL. However, this attack isn’t just limited to email accounts. Any online platform that uses session cookies for convenience, such as e-commerce and financial sites, could be a potential target.

How to Protect Your Business From Session Cookie Theft

To defend against this type of attack, businesses should adopt a proactive approach to cyber security. Here are some steps to help protect your accounts from session cookie theft:

  • Clear Cookies Regularly: Regularly deleting cookies from your browser limits the chances of session cookies being stolen by attackers. Set reminders for your team to clear their browsing data periodically.
  • Avoid Using “Remember Me” on Public or Shared Devices: Remind employees to be cautious with the “remember me” function, especially on shared or public devices where cookies are more vulnerable.
  • Be Wary of Phishing Links: Educate your team on identifying suspicious emails and links. Remind them to hover over links before clicking and to only visit trusted websites with secure connections (HTTPS).
  • Monitor Login Activity: Regularly check the recent login history on accounts to spot any suspicious access. This can often be done directly through the settings of most web-based email accounts.

Why MFA Still Matters

While these recent developments may raise questions about the effectiveness of MFA, it remains one of the most important tools for securing your accounts. Although cookie theft bypasses MFA, most cyber-attacks are still successfully blocked by having this additional layer of security. MFA should remain an essential part of your security setup, alongside good online practices.

Consider Passkeys as a Future Solution

Many tech companies are working on alternatives to the traditional password, such as passkeys. Passkeys link login credentials to your device’s biometric security, making them harder to steal than passwords or session cookies. While passkeys are still catching on, they are set to become more widely available, especially for consumers. In the long run, passkeys may offer a more secure alternative for businesses and individuals alike.

Nxt Steps

Protecting your business from evolving dangers, like these email security threats, requires a solid strategy and the right tools. Regularly updating security practices, educating employees, and reviewing the latest security options can help your business stay secure against emerging cyber threats. If you’d like support in setting up a comprehensive cyber defence for your business, including MFA, passkeys, and cookie management, contact us for help.

Want to learn more about protecting your business against online threats? Click here to explore our cyber security services.