MFA bombing taken to the next level
ID: b21c5e2c-f23d-5ba7-8325-017a55c4a616
STIX ID: report--b21c5e2c-f23d-5ba7-8325-017a55c4a616
Feed Name: Malwarebytes Blog
This piece outlines the TTP of MFA bombing/push-fatigue attacks, where criminals flood victims with authentication or password reset prompts and follow up with spoofed “Apple Support” calls to obtain one-time codes for account takeovers—highlighting Apple ID examples, the role of phone-number targeting, and practical guidance to avoid approval fatigue, ignore unsolicited calls, and use official recovery channels if access is lost.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
