Site icon TheCyberThrone

LinkedIn attack Campaign takes over Accounts

This illustration picture taken on July 24, 2019 in Paris shows the logo of the US social network application Linkedin on the screen of a tablet. (Photo by Martin BUREAU / AFP) (Photo credit should read MARTIN BUREAU/AFP via Getty Images)

Advertisements

An ongoing campaign that came into the limelight recently targeting LinkedIn accounts has led to victims losing control of their accounts or being locked out following repeated login attempts.

Whether the attackers are using brute force methods or credential stuffing isn’t known, but some victims are being locked out following a great number of failed attempts.

Credential stuffing is a popular tactic of attempting to access online accounts using username-password combinations acquired from breached data. In a brute force attack, attackers typically try a lot of common passwords.

Advertisements

The campaign is targeting LinkedIn users all over the world. It pressures the victims that have lost control of their accounts into paying a ransom to avoid having their accounts deleted by the attackers.

Victims are usually made aware of the take-over by a notification that the email address associated with their account has changed.

But, the accounts could also be used to distribute malware, phishing campaigns, or other types of fraud. And if that’s the case, the deletion of the account sounds better to me than having your reputation damaged.

The best defence against brute force attacks, credential stuffing, and other password attacks, is to set up two-step verification.

Advertisements

Setting up MFA for LinkedIn with Okta turned out to be painful because LinkedIn does not provide a QR code but a secret key which is so long that it’s hard to get it right the first, or second time. But since it’s safer than using the SMS 2FA, this is how it’s done:

You will receive an email confirming the change that tells you: From now on, you can use your authenticator app to get a verification code whenever you want to sign in from a new device or browser.

Exit mobile version