Now, a new sophisticated phishing attack that can even work around two-factor authentication (2FA) has been revealed by security experts, with Gmail, Yahoo and Microsoft accounts at particular risk.
It captures sensitive data like username, password and IP address when the unaware victim enters their login credentials before forwarding them to the legitimate website server.
Then the phishing tool becomes like a malign middleman between the user and the legitimate website.
Hackers are now targeting Gmail and Outlook accounts with an attack that can bypass even extra security layers.
Here is how it works so you can avoid falling victim to the latest phishing attack as new tools are being developed.