Overlooked attack method has been used since last August in a rash of account takeovers.