Technology

Phishing Scandal: Cybercriminals Exploit FIDO2 MFA with Sneaky PoisonSeed Attack!

2025-07-19

Author: John Tan

Phishing Alert: New Tactics Unveiled!

In a shocking new development, the PoisonSeed phishing campaign is taking cybercrime to new heights by cleverly bypassing FIDO2 security key protections. This latest scheme exploits the cross-device sign-in feature in WebAuthn, luring unsuspecting users into approving login requests from fake company portals that look surprisingly legitimate!

The Devious Tactics of PoisonSeed!

Known for their brazen phishing attacks aimed at financial fraud, the PoisonSeed hackers have a history of cunning tactics, previously including emails designed to hijack cryptocurrency wallets by sharing sensitive seed phrases. But this latest attack demonstrates a chilling evolution in their methods.

How the Attack Works