Awareness Lessons
5 months ago
MFA Prompt Bombing Exploits User Psychology to Bypass Authentication
MFA prompt bombing attacks exploit the weakest link in multi-factor authentication: human psychology and push notification fatigue. Attackers use stolen credentials to flood users with legitimate MFA prompts, then pose as IT support to pressure victims into approving access. The 2022 Cisco breach shows how this technique can bypass traditional MFA protections, leading to VPN compromise and significant data theft. Push-based MFA notifications create opportunities for social engineering that phishing-resistant methods like FIDO2 keys eliminate.
Tactical Insight
Immediate actions
- Replace push-notification MFA with phishing-resistant methods like FIDO2 keys or hardware tokens
- Implement number-matching or TOTP codes instead of simple approve/deny prompts
- Block known compromised passwords using threat intelligence feeds
Long-term improvements
- Deploy comprehensive security awareness training focused on vishing and MFA manipulation tactics
- Establish clear policies prohibiting IT support from requesting MFA approvals via phone
- Implement conditional access policies that consider device trust and location context
Detection measures
- Monitor for unusual patterns of repeated MFA requests from the same user account
- Set up alerts for MFA approvals outside normal business hours or geographic locations