How To Stop MFA Fatigue Attacks
ID: 17fe0c12-378c-5e98-979f-7f8b30831998
STIX ID: report--17fe0c12-378c-5e98-979f-7f8b30831998
Feed Name: Arctic Wolf
Threat Score
This report explains MFA fatigue (also called prompt- or push-bombing), an access-oriented attack technique where an adversary with stolen credentials repeatedly sends MFA approval requests to a user until the user approves, enabling account takeover; it details attack stages, provides a real-world example, discusses the connection to credential theft and BEC, and lists defensive measures (rate-limiting prompts, alternative authenticators, contextual checks, training, and monitoring).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
