Bottom line: Security leaders must verify user account access with two-factor authentication (2FA) to prevent suspected Russian hackers from hijacking legitimate accounts.
What's happening: The attacks involve leveraging Google OAuth and WhatsApp to link to targeted accounts, exploiting vulnerabilities in the systems of universities such as Stanford University and the University of California, Berkeley.
What to do: Implementing 2FA for all users, particularly those with access to sensitive information, is crucial to prevent these types of attacks.