LIVE MONITORING
Medium Campaign N/A

Medium: Widespread MFA Fatigue Campaign

Affected Systems

Organizations using push-based MFA

A coordinated campaign is targeting organizations using push-based multi-factor authentication, bombarding users with approval requests until they accidentally or deliberately approve one. This technique was used in the Uber and Cisco breaches.

Mitigation Steps

  1. Switch to number-matching MFA
  2. Implement FIDO2/WebAuthn where possible
  3. Set rate limits on MFA push notifications
  4. Train users to report unsolicited MFA prompts