logo

Recent ‘MFA Bombing’ Attacks Targeting Apple Users

ID: b1be985f-cff7-5506-bf5c-c7bb27c350df

STIX ID: report--b1be985f-cff7-5506-bf5c-c7bb27c350df

Feed Name: Krebs on Security

Threat Score
68/100

Date Published: 2024-03-26

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Multiple Apple customers reported a phishing campaign that inundates victims with system password-reset prompts (MFA fatigue or "push bombing") so attackers can follow up with spoofed Apple Support calls requesting one-time codes; if provided the attackers can reset Apple ID passwords and remotely wipe devices. Victims experienced dozens to hundreds of prompts across devices and watches; enabling Apple Recovery Keys did not stop the prompts, and testing shows Apple’s forgot-password flow can trigger alerts using the phone number on file. The report suggests attackers may be abusing a rate-limiting weakness in Apple’s password reset process and offers mitigation ideas such as using obscure VOIP numbers or email aliases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.