12,169.85-54.7
Stock Analysis, IPO, Mutual Funds, Bonds & More

Can't spot a YouTube channel? Creators struck by massive account hijacks, tweet complaints

Hackers were capable of bypassing two-factor authentication on users' accounts.

IANS|
Sep 24, 2019, 04.25 PM IST
0Comments
YouTube can be a viable career choice — provided you have the dedication and perseverance required to see it through. Don’t worry if you’re completely new to the idea of video content creation — it’s simpler than you think. Karan Bajaj tells you all you need to get started.
YouTube can be a viable career choice — provided you have the dedication and perseverance required to see it through. Don’t worry if you’re completely new to the idea of video content creation — it’s simpler than you think. Karan Bajaj tells you all you need to get started.
SAN FRANCISCO: YouTube creators, particularly in the auto-tuning and car review community, have become target of a massive wave of account hijacks, a media report said.

The account hacks are the result of a coordinated campaign where hackers use phishing emails to lure victims on fake Google login pages from where they collect users' account credentials, an investigation by ZDNet found.

The attacks appear to have affected creators from India as well, as Twitter is flooded with complaints about missing channels from YouTube.

"I am a subscriber & also a big fan of his work #Musafirakajoshi and Somebody hacked my brother Rahul joshi's YouTube channel #Musafirakajoshi @YouTubeIndia Please get in touch with him as soon as possible. @YouTubeIndia And bring his channel back as soon," wrote one Twitter user.





"The recent phishing attacks on YouTube are an escalation of a classic scheme, in which users are lured to fake login pages, where they enter legitimate credentials. Cybercriminals are always looking for the weakest link in the cybersecurity protecting valuable assets; in this case, it was users," Jonathan Knudsen, Senior Security Strategist at Synopsys Integrity Group.

According to a YouTube video from Life of Palos uploaded over the weekend, hackers were capable of bypassing two-factor authentication on users' accounts.

Hackers targeting YouTubers might have used Modlishka, a reverse proxy-based phishing toolkit that can also intercept 2FA SMS codes, he suggested.

The best proactive defence against such attacks is education. With the right knowledge, many fewer users would have fallen victim to these attacks.

"While SMS 2-factor authentication is better than no second factor, this incident is still a reminder of its weaknesses which is why NIST stopped recommending its use back in 2016," said Bill Lummis, Technical Program Manager at HackerOne.

"It is important that the industry moves towards newer tools such as time-based One-time Password (TOTP), which recycles numbers every 30-90 seconds on a physical device, or Universal 2nd Factor (U2F), such as Yubikey, given that attacks like this will only become easier to execute over time," Lummis said.

5-Step YouTuber Guide For Newbies

of 7
Next
Prev
Play Slideshow

Getting Started

28 May, 2019
YouTube can be a viable career choice — provided you have the dedication and perseverance required to see it through. Don’t worry if you’re completely new to the idea of video content creation — it’s simpler than you think. Karan Bajaj tells you all you need to get started.
Next

Also Read

Game set for big bucks on YouTube arena

New YouTube rules on kids’ content to hit creators’ revenue

Film maker wins copyright infringement case against Google, YouTube

YouTube to make verification rules stricter for influencers

What's trending? YouTube Charts launched in India

Comments
Add Your Comments
Commenting feature is disabled in your country/region.

Popular Categories


Other useful Links


Copyright © 2020 Bennett, Coleman & Co. Ltd. All rights reserved. For reprint rights: Times Syndication Service