{"id":12438,"date":"2024-06-14T14:27:12","date_gmt":"2024-06-14T11:27:12","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=12438"},"modified":"2024-06-14T14:27:12","modified_gmt":"2024-06-14T11:27:12","slug":"when-two-factor-authentication-useless","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/when-two-factor-authentication-useless\/12438\/","title":{"rendered":"\u0130ki fakt\u00f6rl\u00fc kimlik do\u011frulama i\u015fe yaramad\u0131\u011f\u0131nda"},"content":{"rendered":"<p>Tek kullan\u0131ml\u0131k \u015fifrelerin (<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/types-of-two-factor-authentication\/11585\/\" target=\"_blank\" rel=\"noopener\">OTP\u2019ler<\/a>) kullan\u0131ld\u0131\u011f\u0131 iki fakt\u00f6rl\u00fc kimlik do\u011frulama (2FA) art\u0131k kimlik av\u0131, sosyal m\u00fchendislik, hesap h\u0131rs\u0131zl\u0131\u011f\u0131 ve di\u011fer siber tehlikelere kar\u015f\u0131 her derde deva bir \u00e7\u00f6z\u00fcm olarak g\u00f6r\u00fclmektedir. S\u00f6z konusu hizmet, oturum a\u00e7ma s\u0131ras\u0131nda bir OTP talep ederek kullan\u0131c\u0131 do\u011frulamas\u0131 i\u00e7in ek bir koruyucu katman sa\u011flar. Kod, do\u011frudan kullan\u0131c\u0131n\u0131n cihaz\u0131ndaki \u00f6zel bir uygulamada olu\u015fturulabilir, ancak ne yaz\u0131k ki \u00e7ok az ki\u015fi bir <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">kimlik do\u011frulama uygulamas\u0131<\/a>\u00a0y\u00fckleme ve yap\u0131land\u0131rma zahmetine girer. Bu nedenle, siteler genellikle bir metin, e-posta, anl\u0131k bildirim, anl\u0131k mesaj veya hatta sesli arama \u015feklinde bir do\u011frulama kodu g\u00f6nderir.<\/p>\n<p>S\u0131n\u0131rl\u0131 bir s\u00fcre i\u00e7in ge\u00e7erli olan bu kod, g\u00fcvenli\u011fi \u00f6nemli \u00f6l\u00e7\u00fcde art\u0131rsa da sihirli bir de\u011fnek de\u011fildir: <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/what-is-two-factor-authentication\/11564\/\" target=\"_blank\" rel=\"noopener\">2FA<\/a> ile bile ki\u015fisel hesaplar OTP botlar\u0131na (kullan\u0131c\u0131lar\u0131 sosyal m\u00fchendislik yoluyla OTP\u2019lerini vermeleri i\u00e7in kand\u0131ran otomatik yaz\u0131l\u0131mlar) kar\u015f\u0131 savunmas\u0131z kalmaya devam eder.<\/p>\n<p>Peki bu botlar kimlik av\u0131nda nas\u0131l bir rol oynar ve nas\u0131l \u00e7al\u0131\u015f\u0131r? Detaylar i\u00e7in okumaya devam edin\u2026<\/p>\n<h2>OTP botlar\u0131 nas\u0131l \u00e7al\u0131\u015f\u0131r?<\/h2>\n<p>Bir web taray\u0131c\u0131s\u0131ndaki kontrol paneli veya Telegram arac\u0131l\u0131\u011f\u0131yla kontrol edilen bu botlar, bankalar gibi me\u015fru kurulu\u015flar\u0131 taklit ederek, kurban\u0131 g\u00f6nderilen bir OTP\u2019yi if\u015fa etmesi i\u00e7in kand\u0131rmay\u0131 ama\u00e7lar. Olaylar \u015f\u00f6yle geli\u015fir:<\/p>\n<ol>\n<li>Doland\u0131r\u0131c\u0131, kurban\u0131n giri\u015f bilgilerini (parola d\u00e2hil) elde ettikten sonra (bu i\u015flemin nas\u0131l yap\u0131ld\u0131\u011f\u0131n\u0131 a\u015fa\u011f\u0131da anlat\u0131yoruz) kurban\u0131n hesab\u0131na giri\u015f yapar ve bir OTP girmesi istenir.<\/li>\n<li>Kurban OTP\u2019yi telefonuna al\u0131r.<\/li>\n<li>OTP botu kurban\u0131 arar ve \u00f6nceden kaydedilmi\u015f bir sosyal m\u00fchendislik senaryosu kullanarak al\u0131nan kodu girmesini ister.<\/li>\n<li>Masum kurban, g\u00f6r\u00fc\u015fme s\u0131ras\u0131nda kodu telefonuna girer.<\/li>\n<li>Kod, sald\u0131rgan\u0131n Telegram botuna iletilir.<\/li>\n<li>Doland\u0131r\u0131c\u0131, kurban\u0131n hesab\u0131na eri\u015fim kazan\u0131r.<\/li>\n<\/ol>\n<p>OTP botunun temel i\u015flevi kurban\u0131 aramakt\u0131r ve doland\u0131r\u0131c\u0131l\u0131\u011f\u0131n ba\u015far\u0131s\u0131 botun ne kadar ikna edici oldu\u011funa ba\u011fl\u0131d\u0131r zira OTP\u2019lerin \u00f6mr\u00fc k\u0131sad\u0131r, bu nedenle bir telefon g\u00f6r\u00fc\u015fmesi s\u0131ras\u0131nda ge\u00e7erli bir kod elde etme \u015fans\u0131 di\u011fer yollardan \u00e7ok daha y\u00fcksektir. Bu nedenle OTP botlar\u0131, \u00e7a\u011fr\u0131 parametrelerinde ince ayar yapmak i\u00e7in \u00e7ok say\u0131da se\u00e7enek sunar.<\/p>\n<div id=\"attachment_12445\" style=\"width: 935px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14141857\/when-two-factor-authentication-useless-1.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-12445\" class=\"size-full wp-image-12445\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14141857\/when-two-factor-authentication-useless-1.png\" alt=\"OTP botu \u00f6zelliklerinin listesi\" width=\"925\" height=\"813\"><\/a><p id=\"caption-attachment-12445\" class=\"wp-caption-text\">Bu OTP botu; birden fazla dilde haz\u0131rlanm\u0131\u015f ve \u00f6zelle\u015ftirilmi\u015f komut dosyalar\u0131, 12 \u00e7al\u0131\u015fma modu ve hatta 7\/24 teknik destek gibi bir d\u00fczineden fazla \u00f6zelli\u011fe sahiptir.<\/p><\/div>\n<p>OTP botlar\u0131 bir sekt\u00f6rd\u00fcr, bu nedenle doland\u0131r\u0131c\u0131lar i\u015fe ilk olarak kriptoda haftal\u0131k 420 dolara mal olan bir abonelik sat\u0131n alarak ba\u015flarlar. Daha sonra botu kurban\u0131n ad\u0131, numaras\u0131 ve banka bilgileriyle beslerler ve taklit etmek istedikleri kurulu\u015fu se\u00e7erler.<\/p>\n<div id=\"attachment_12446\" style=\"width: 974px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14142048\/when-two-factor-authentication-useless-2.jpeg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-12446\" class=\"size-full wp-image-12446\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14142048\/when-two-factor-authentication-useless-2.jpeg\" alt=\"OTP'leri yakalama ama\u00e7l\u0131 Telegram bot men\u00fcs\u00fc\" width=\"964\" height=\"1173\"><\/a><p id=\"caption-attachment-12446\" class=\"wp-caption-text\">Kullan\u0131c\u0131 dostu bot men\u00fcs\u00fcne programlama becerisi olmayan doland\u0131r\u0131c\u0131lar bile eri\u015febilir<\/p><\/div>\n<p>Doland\u0131r\u0131c\u0131lar, inand\u0131r\u0131c\u0131l\u0131k i\u00e7in, kurban\u0131n telefonunda g\u00f6r\u00fcnt\u00fclenen ve araman\u0131n geldi\u011fi g\u00f6r\u00fcnen telefon numaras\u0131n\u0131 belirterek yan\u0131ltma i\u015flevini etkinle\u015ftirebilir. Ayr\u0131ca botun dilini ve hatta sesini bile \u00f6zelle\u015ftirebilirler. T\u00fcm sesler yapay zeka taraf\u0131ndan \u00fcretilir, bu nedenle \u00f6rne\u011fin OTP botu \u0130ngilizceyi Hint aksan\u0131yla veya Kastilya \u0130spanyolcas\u0131yla \u201ckonu\u015fabilir\u201d. Bir arama sesli mesaja y\u00f6nlendirilirse, bot telefonu kapatmas\u0131 gerekti\u011fini bilir. Ve her \u015feyin do\u011fru yap\u0131land\u0131r\u0131ld\u0131\u011f\u0131ndan emin olmak i\u00e7in, doland\u0131r\u0131c\u0131lar bir sald\u0131r\u0131 ba\u015flatmadan \u00f6nce kendi test numaralar\u0131n\u0131 arayarak OTP bot ayarlar\u0131n\u0131 kontrol edebilirler.<\/p>\n<p>Baz\u0131 OTP botlar\u0131, kurban\u0131n araman\u0131n ger\u00e7ek oldu\u011funa inanmas\u0131 ihtimalini g\u00fc\u00e7lendirmek i\u00e7in, numaray\u0131 \u00e7evirmeden \u00f6nce yakla\u015fan arama hakk\u0131nda bir k\u0131sa mesaj uyar\u0131s\u0131 g\u00f6nderebilir. Bu, hedefin dikkatini da\u011f\u0131t\u0131r \u00e7\u00fcnk\u00fc ilk bak\u0131\u015fta \u015f\u00fcpheli bir \u015fey yoktur: \u201cBankadan\u201d gelecek bir aramayla ilgili bir metin bildirimi al\u0131rs\u0131n\u0131z ve birka\u00e7 dakika sonra da ararlar, bu bir aldatmaca olamaz, de\u011fil mi? Ama ne yaz\u0131k ki \u00f6yledir.<\/p>\n<p>Bir arama s\u0131ras\u0131nda baz\u0131 botlar yaln\u0131zca OTP de\u011fil, banka kart\u0131 numaras\u0131 ve son kullanma tarihi, g\u00fcvenlik kodu veya PIN, do\u011fum tarihi, belge ayr\u0131nt\u0131lar\u0131 gibi ba\u015fka veriler de talep edebilir.<\/p>\n<p>OTP botlar\u0131n\u0131n i\u00e7 i\u015fleyi\u015fini daha derinlemesine incelemek i\u00e7in <a href=\"https:\/\/securelist.com\/2fa-phishing\/112805\/\" target=\"_blank\" rel=\"noopener\">Securelist raporumuza<\/a> g\u00f6z at\u0131n.<\/p>\n<h2>Yaln\u0131zca botla de\u011fil<\/h2>\n<p>OTP botlar\u0131 2FA\u2019y\u0131 atlamak i\u00e7in etkili ara\u00e7lar olsa da, kurban\u0131n ki\u015fisel verileri olmadan tek ba\u015flar\u0131na i\u015fe yaramazlar. Sald\u0131rganlar\u0131n hesaba eri\u015fim sa\u011flamak i\u00e7in en az\u0131ndan kurban\u0131n kullan\u0131c\u0131 ad\u0131, telefon numaras\u0131 ve parolas\u0131na ihtiya\u00e7lar\u0131 vard\u0131r. Ancak hedef hakk\u0131nda ne kadar \u00e7ok bilgiye sahip olurlarsa (tam ad, do\u011fum tarihi, adres, e-posta, banka kart\u0131 bilgileri), onlar i\u00e7in o kadar iyi olur. Bu veriler \u00e7e\u015fitli yollarla elde edilebilir:<\/p>\n<ul>\n<li><strong>Karanl\u0131k a\u011fdan: <\/strong>Bilgisayar korsanlar\u0131 d\u00fczenli olarak veritabanlar\u0131n\u0131 karanl\u0131k a\u011fda sat\u0131\u015fa \u00e7\u0131kararak doland\u0131r\u0131c\u0131lar\u0131n parolalar, banka kart\u0131 numaralar\u0131 ve di\u011fer veriler gibi giri\u015f bilgilerini sat\u0131n almas\u0131na olanak tan\u0131r. \u00c7ok yeni olmayabilirler, ancak \u00e7o\u011fu kullan\u0131c\u0131 ne yaz\u0131k ki parolalar\u0131n\u0131 y\u0131llarca de\u011fi\u015ftirmez ve di\u011fer bilgiler zaten daha da uzun s\u00fcre ge\u00e7erlili\u011fini korur. Bu arada, <a href=\"https:\/\/www.kaspersky.com.tr\/premium?icid=tr_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a> telefon numaran\u0131z\u0131 veya e-posta adresinizi i\u00e7eren herhangi bir veri ihlalini, <a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u00a0ise parolalar\u0131n ele ge\u00e7irilme olaylar\u0131n\u0131 an\u0131nda size bildirir.<\/li>\n<li><strong>A\u00e7\u0131k kaynakl\u0131 istihbarattan: <\/strong>Bazen veri tabanlar\u0131 \u201cnormal\u201d web \u00fczerinden kamuya s\u0131zd\u0131r\u0131lmakta, ancak medyada yer almalar\u0131 nedeniyle h\u0131zla g\u00fcncelli\u011fini yitirmektedir. \u00d6rne\u011fin, m\u00fc\u015fteri veri ihlalini ke\u015ffeden bir \u015firketin standart uygulamas\u0131, s\u0131zan t\u00fcm hesaplar\u0131n parolalar\u0131n\u0131 s\u0131f\u0131rlamak ve kullan\u0131c\u0131lardan bir sonraki giri\u015flerinde yeni bir parola olu\u015fturmalar\u0131n\u0131 istemektir.<\/li>\n<li><strong>Kimlik av\u0131 sald\u0131r\u0131s\u0131 yoluyla: <\/strong>Bu y\u00f6ntemin di\u011ferlerine g\u00f6re yads\u0131namaz bir avantaj\u0131 vard\u0131r: Kimlik av\u0131 ger\u00e7ek zamanl\u0131 olarak ger\u00e7ekle\u015febildi\u011fi i\u00e7in kurban\u0131n verilerinin g\u00fcncel oldu\u011fu garantidir.<\/li>\n<\/ul>\n<p><a href=\"https:\/\/securelist.com\/phishing-kit-market-whats-inside-off-the-shelf-phishing-packages\/106149\/\" target=\"_blank\" rel=\"noopener\">Kimlik av\u0131 kitleri (phishkit)<\/a>, doland\u0131r\u0131c\u0131lar\u0131n ki\u015fisel verileri toplamak i\u00e7in otomatik olarak ikna edici sahte web siteleri olu\u015fturmas\u0131na olanak tan\u0131yan ara\u00e7lard\u0131r. Zamandan tasarruf sa\u011flarlar ve siber su\u00e7lular\u0131n ihtiya\u00e7 duyduklar\u0131 t\u00fcm kullan\u0131c\u0131 bilgilerini tek bir sald\u0131r\u0131da toplamalar\u0131na izin verirler (bu durumda OTP botlar\u0131 kimlik av\u0131 sald\u0131r\u0131s\u0131n\u0131n sadece bir par\u00e7as\u0131d\u0131r).<\/p>\n<p>\u00d6rne\u011fin, \u00e7ok a\u015famal\u0131 bir kimlik av\u0131 sald\u0131r\u0131s\u0131 \u015fu \u015fekilde ger\u00e7ekle\u015febilir: Kurban, s\u00f6zde bir banka, ma\u011faza veya ba\u015fka bir kurulu\u015ftan ki\u015fisel hesap verilerini g\u00fcncellemeye davet eden bir mesaj al\u0131r. Bu mesaj\u0131n ekinde bir <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/how-to-protect-yourself-from-phishing\/10132\/\" target=\"_blank\" rel=\"noopener\">kimlik av\u0131<\/a> ba\u011flant\u0131s\u0131 bulunmaktad\u0131r. Beklenti, <em>orijinaliyle neredeyse ayn\u0131<\/em> olan bir siteye girdikten sonra kurban\u0131n giri\u015f bilgilerini girmesi ve kimlik avc\u0131lar\u0131n\u0131n da bu bilgileri \u00e7almas\u0131d\u0131r. Ve sald\u0131rganlar bunlar\u0131 do\u011frudan kurban\u0131n ger\u00e7ek hesab\u0131na giri\u015f yapmak i\u00e7in kullanacaklard\u0131r.<\/p>\n<p>Hesap 2FA korumal\u0131ysa, doland\u0131r\u0131c\u0131lar kimlik av\u0131 kiti kontrol paneline, kimlik av\u0131 sitesinde bir OTP giri\u015f sayfas\u0131 g\u00f6r\u00fcnt\u00fclemesi i\u00e7in komut verir. Kurban kodu girdi\u011finde, kimlik avc\u0131lar\u0131 ger\u00e7ek hesaba tam eri\u015fim elde eder ve \u00f6rne\u011fin banka hesaplar\u0131n\u0131 bo\u015faltabilirler.<\/p>\n<p>Ama i\u015f bununla bitmez. Doland\u0131r\u0131c\u0131lar, m\u00fcmk\u00fcn oldu\u011funca fazla ki\u015fisel bilgi alma f\u0131rsat\u0131n\u0131 de\u011ferlendirerek, kullan\u0131c\u0131ya zorunlu bir gereklilik olarak \u201ckimlik bilgilerini onaylamas\u0131\u201d i\u00e7in bask\u0131 yapar. Sald\u0131rganlar kontrol paneli arac\u0131l\u0131\u011f\u0131yla e-posta adresi, banka kart\u0131 numaras\u0131 ve di\u011fer hassas verileri ger\u00e7ek zamanl\u0131 olarak talep edebilirler. Bu bilgiler kurban\u0131n di\u011fer hesaplar\u0131na sald\u0131rmak i\u00e7in kullan\u0131labilir. \u00d6rne\u011fin, kurban\u0131n posta kutusuna ele ge\u00e7irilen parolayla eri\u015fmeyi deneyebilirler. Sonu\u00e7ta pek \u00e7ok insan ayn\u0131 parolay\u0131 t\u00fcm hesaplar\u0131 i\u00e7in olmasa da bir\u00e7ok hesap i\u00e7in tekrar kullan\u0131r! E-postaya eri\u015fim sa\u011flad\u0131ktan sonra, sald\u0131rganlar ger\u00e7ekten kasaya girmi\u015f olurlar ve \u00f6rne\u011fin, posta kutusu \u015fifresini de\u011fi\u015ftirebilirler ya da posta kutusu i\u00e7eri\u011finin k\u0131sa bir analizinden sonra bu adrese ba\u011fl\u0131 di\u011fer t\u00fcm hesaplar i\u00e7in parola s\u0131f\u0131rlama talebinde bulunabilirler.<\/p>\n<div id=\"attachment_12447\" style=\"width: 502px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14142219\/when-two-factor-authentication-useless-3.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-12447\" class=\"size-full wp-image-12447\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2024\/06\/14142219\/when-two-factor-authentication-useless-3.png\" alt=\"Kimlik av\u0131 kiti kontrol panelinde ek bilgi talebi i\u00e7in se\u00e7enekler\" width=\"492\" height=\"725\"><\/a><p id=\"caption-attachment-12447\" class=\"wp-caption-text\">Kimlik av\u0131 kiti kontrol panelinde ek bilgi talebi i\u00e7in se\u00e7enekler<\/p><\/div>\n<h2>Hesaplar\u0131n\u0131z\u0131 nas\u0131l g\u00fcvende tutabilirsiniz?<\/h2>\n<ul>\n<li><strong>Hem sizin hem de ailenizin e-posta adresleri ve telefon numaralar\u0131yla ba\u011flant\u0131l\u0131 hesaplar\u0131n\u0131z\u0131 etkileyen veri s\u0131z\u0131nt\u0131lar\u0131n\u0131 otomatik olarak taramak i\u00e7in her zaman <a href=\"https:\/\/www.kaspersky.com.tr\/premium?icid=tr_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener\">Kaspersky Premium<\/a><\/strong>\u00a0<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/kaspersky-international-password-day-2024\/12275\/\" target=\"_blank\" rel=\"noopener\">kullan\u0131n<\/a>. Bir ihlal tespit edildi\u011finde, uygulaman\u0131n tavsiyelerine uyun (en az\u0131ndan parolan\u0131z\u0131 hemen de\u011fi\u015ftirin).<\/li>\n<li><strong>Durup dururken bir OTP al\u0131rsan\u0131z dikkatli olun<\/strong>. Birisi sizi hacklemeye \u00e7al\u0131\u015f\u0131yor olabilir. Bu durumda ne yap\u0131laca\u011f\u0131na ili\u015fkin ayr\u0131nt\u0131lar i\u00e7in <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/unexpected-login-codes-otp-2fa\/12049\/\" target=\"_blank\" rel=\"noopener\">talimatlar\u0131m\u0131za<\/a> bak\u0131n.<\/li>\n<li><strong><a href=\"https:\/\/www.kaspersky.com.tr\/password-manager?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener\">Kaspersky Password Manager<\/a>\u00a0ile t\u00fcm hesaplar\u0131n\u0131z i\u00e7in g\u00fc\u00e7l\u00fc ve benzersiz parolalar olu\u015fturun.<\/strong> Doland\u0131r\u0131c\u0131lar parolan\u0131z\u0131 bilmedikleri s\u00fcrece OTP botlar\u0131 ile size sald\u0131ramazlar, bu nedenle <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/kaspersky-international-password-day-2024\/12275\/\" target=\"_blank\" rel=\"noopener\">karma\u015f\u0131k parolalar olu\u015fturun ve bunlar\u0131 g\u00fcvenli bir \u015fekilde saklay\u0131n<\/a>.<\/li>\n<li><strong>Ki\u015fisel verileri veya OTP\u2019yi girmek i\u00e7in bir ba\u011flant\u0131 i\u00e7eren bir mesaj al\u0131rsan\u0131z, URL\u2019yi iki kez kontrol edin. <\/strong>Doland\u0131r\u0131c\u0131lar\u0131n en sevdi\u011fi numaralardan biri, <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/typosquatting\/\" target=\"_blank\" rel=\"noopener\">adres \u00e7ubu\u011funda sadece birka\u00e7 karakter de\u011fi\u015ftirerek<\/a> sizi bir kimlik av\u0131 sitesine y\u00f6nlendirmektir. Herhangi bir hassas veri girmeden \u00f6nce ger\u00e7ek bir sitede oldu\u011funuzu do\u011frulamak i\u00e7in her zaman bir dakikan\u0131z\u0131 ay\u0131r\u0131n. Bu arada, <a href=\"https:\/\/www.kaspersky.com.tr\/home-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_blo_lnk_sm-team______\" target=\"_blank\" rel=\"noopener\">korumam\u0131z<\/a>\u00a0t\u00fcm kimlik av\u0131 yeniden y\u00f6nlendirme giri\u015fimlerini engeller.<\/li>\n<li><strong>OTP\u2019lerinizi asla kimseyle payla\u015fmay\u0131n veya bir arama s\u0131ras\u0131nda telefonunuzun tu\u015f tak\u0131m\u0131na girmeyin.<\/strong> Bankalar\u0131n, ma\u011fazalar\u0131n veya hizmetlerin yasal \u00e7al\u0131\u015fanlar\u0131n\u0131n ve hatta emniyet g\u00fc\u00e7lerinin asla OTP\u2019nizi istemeyece\u011fini unutmay\u0131n.<\/li>\n<li>Oyunda bir ad\u0131m \u00f6nde olun<strong>. <\/strong>Siber ortamdaki hayat\u0131n\u0131z\u0131 <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/subscribe\/\" target=\"_blank\" rel=\"noopener\">daha g\u00fcvenli hale getirmek i\u00e7in<\/a> blogumuza abone olun.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-generic\">\n","protected":false},"excerpt":{"rendered":"<p>\u0130ki fakt\u00f6rl\u00fc kimlik do\u011frulama, hesab\u0131n\u0131z\u0131 h\u0131rs\u0131zl\u0131\u011fa kar\u015f\u0131 korur, ta ki siz tek kullan\u0131ml\u0131k \u015fifrenizi verene kadar.<\/p>\n","protected":false},"author":2710,"featured_media":12439,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1351],"tags":[1624,1626,612,2026,1074,2706,2094],"class_list":{"0":"post-12438","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threats","8":"tag-2fa","9":"tag-dolandircilik","10":"tag-dolandiricilik","11":"tag-iki-faktorlu-kimlik-dogrulama","12":"tag-kimlik-avi","13":"tag-otp","14":"tag-sahtekarlik"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/when-two-factor-authentication-useless\/12438\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/when-two-factor-authentication-useless\/27546\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/when-two-factor-authentication-useless\/22864\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/when-two-factor-authentication-useless\/11721\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/when-two-factor-authentication-useless\/30217\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/when-two-factor-authentication-useless\/27696\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/when-two-factor-authentication-useless\/27429\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/when-two-factor-authentication-useless\/30092\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/when-two-factor-authentication-useless\/28985\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/when-two-factor-authentication-useless\/37627\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/when-two-factor-authentication-useless\/51434\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/when-two-factor-authentication-useless\/21938\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/when-two-factor-authentication-useless\/22682\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/when-two-factor-authentication-useless\/31333\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/when-two-factor-authentication-useless\/36613\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/when-two-factor-authentication-useless\/29134\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/when-two-factor-authentication-useless\/27872\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/when-two-factor-authentication-useless\/33690\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/when-two-factor-authentication-useless\/33354\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/dolandircilik\/","name":"doland\u0131rc\u0131l\u0131k"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/12438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2710"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=12438"}],"version-history":[{"count":7,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/12438\/revisions"}],"predecessor-version":[{"id":12449,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/12438\/revisions\/12449"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/12439"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=12438"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=12438"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=12438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}