Recent ‘MFA Bombing’ Attacks Targeting Apple Users
ID: b1be985f-cff7-5506-bf5c-c7bb27c350df
STIX ID: report--b1be985f-cff7-5506-bf5c-c7bb27c350df
Feed Name: Krebs on Security
Multiple Apple customers reported a phishing campaign that inundates victims with system password-reset prompts (MFA fatigue or "push bombing") so attackers can follow up with spoofed Apple Support calls requesting one-time codes; if provided the attackers can reset Apple ID passwords and remotely wipe devices. Victims experienced dozens to hundreds of prompts across devices and watches; enabling Apple Recovery Keys did not stop the prompts, and testing shows Apple’s forgot-password flow can trigger alerts using the phone number on file. The report suggests attackers may be abusing a rate-limiting weakness in Apple’s password reset process and offers mitigation ideas such as using obscure VOIP numbers or email aliases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
