Think You’re Safe Because of MFA? Think Again — Hackers Are Now Raiding the Cookie Jar

The News: It’s not unusual for organizations to implement multi-factor authentication (MFA) protocols and think they’re safe from hackers. Today, that’s not so much the case. Hackers are using stolen app and active session cookies as a way to circumvent multi-factor identification barriers, according to British cyber security company Sophos. The sale of cookies with active sessions on encrypted networks threatens the current security standard for cloud-based services and opens up a massive amount of sensitive information to unauthorized access. This is a bad thing. Like, a “we better fix this fast” bad thing. Read more about the news on Tech Radar.

Think You’re Safe Because of MFA? Think Again — Hackers Are Now Raiding the Cookie Jar

Analyst Take: Part of the preaching the gospel about cybersecurity best practices often includes singing the praises of multi-factor authentication. Today, hackers are finding a clever away around the barriers MFA attempts to put in their way by focusing on cookies instead. And it’s smart.

When a user clicks through a cookie opt-in (which most of us do countless times a day), they’re opening a “session.” That session is essentially an amount of time each user can visit before being asked to log in again. Depending on the platform, session cookies can remain active for days or weeks. That’s the latest hacker playground. By focusing on and snatching fresh cookies for sessions that remain active, hackers can access information without being required to authenticate.

Sophos News’ Sean Gallagher laid out the breadth of apps and data being bought and sold on underground forums as the popularity of session-hijacking grows, “Information-stealing malware [which] can be purchased through underground forums” Gallagher explained based on Sophos data, “are often used by entry-level criminals to collect cookies and other credentials in bulk for sale to criminal marketplaces.”

But it only gets more advanced from there. The Lapsus$ extortion group alleged that they successfully accessed EA’s Slack channel via a purchased session cookie, allowing them to grab 780gb of data before the gaming giant could shut them down. Gallagher suggests that skilled cookie-thieves could eventually grab session data from users’ browsers in real-time.

So, How Do We Put a Lid on This Cookie Jar?

How do we adapt cybersecurity behavior across organizations to counter this threat? Knowing the risk posed by cookies is a good start. And let this be a reminder that it’s not a good idea to count on multi-factor authentication alone as the be all, end all protection. Beef up your firewall. Know what your security team is doing to reduce vulnerabilities, Session-length can be adjusted by an admin in a lot of apps, so that’s a good place to start reducing active sessions. Educate your team about the dangers posed by cookies and teach them (and remind them on the regular) to take the time to opt-out of unnecessary cookies. Also, take a good look at the settings for the apps you use internal comms, like Slack, which have notoriously long session-lengths. Hackers continue to evolve their strategies and look for vulnerabilities and stealing active session cookies is pretty smart. Learn from these mistakes regarding the vulnerability of active sessoin cookies and MFA and evolve your internal security operations accordingly.

Disclosure: Futurum Research is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum Research as a whole.

Other insights from Futurum Research:

Full Impact of REvil Ransomeware Attack on Kaseya Becomes Apparent

The Apple Meta Hack Breaking Down How It Happened and Exploring Some of the Cybersecurity Dangers Ahead

IBM’s Cost of a Data Breach Report Reveals Data Breach Cost is at an All-Time High Raising Consumer Prices

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
So This Is How AIs Attack- Observations From the OpenAI & Hugging Face Incident
July 24, 2026

So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident

Fernando Montenegro and Mitch Ashley, VPs at Futurum, read the OpenAI and Hugging Face agentic incident as a live test of enterprise readiness to detect and contain AI agents that...
ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth
July 23, 2026

ServiceNow Q2 FY 2026: AI, Security, and Workflow Expansion Fuel Growth

Futurum Research analyzes ServiceNow Q2 FY 2026 earnings, focusing on AI Control Tower adoption, security expansion, and workflow demand....
Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment
July 23, 2026

Alphabet Q2 FY 2026: Google Cloud Leads Growth Amid Rising AI Investment

Futurum Research analyzes Alphabet’s Q2 FY 2026 earnings, focusing on cloud AI demand, Gemini adoption, Search monetization, and rising AI infrastructure spending....
Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?
July 23, 2026

Why Did a Cryptomining Campaign Fail Despite 199 RubyGems?

Mend.io's security team identified 199 malicious RubyGems and achieved complete takedown within hours, intercepting a cryptomining campaign before execution and demonstrating the critical importance of continuous open-source monitoring....
Hugging Face Breach: A Wake-Up Call for AI Agent Security
July 23, 2026

Hugging Face Breach: A Wake-Up Call for AI Agent Security

The Hugging Face breach reveals how autonomous AI agents exploit code flaws to harvest credentials and move laterally at machine speed. Enterprise leaders now recognize identity security as urgent, with...
Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation
July 22, 2026

Intel Foundry Lands Fortinet SP6 as Custom Silicon Validation

Brendan Burke and Fernando Montenegro, analysts at Futurum, share their insights on the Intel-Fortinet SP6 collaboration, what it validates about Intel Foundry's custom silicon strategy, and why the supply chain...

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.