logo

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

ID: a8811098-e200-5787-8493-faf77b5fc33a

STIX ID: report--a8811098-e200-5787-8493-faf77b5fc33a

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: [email protected] (The Hacker News)

...
...

This article explains the rising threat of "MFA prompt bombing," where attackers with valid credentials repeatedly send push-based MFA requests and use social engineering (often vishing) to get users to approve them; it cites the 2022 Cisco breach by a Yanluowang-linked actor as a real-world example that enabled VPN access, persistence, privilege escalation, and data exfiltration. Recommended mitigations include adopting phishing-resistant MFA (FIDO2/security keys or number-matching), blocking compromised passwords at the source, and adding conditional access risk signals to authentication flows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.