Misplaced Pages

Multi-factor authentication fatigue attack

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
Computer security attack

A multi-factor authentication fatigue attack (also MFA fatigue attack or MFA bombing) is a computer security attack against multi-factor authentication that makes use of social engineering. When MFA applications are configured to send push notifications to end users, an attacker can send a flood of login attempts in the hope that a user will click on accept at least once.

In September 2022 Uber security was breached by a member of Lapsus$ using a multi-factor fatigue attack.

In 2022, Microsoft has deployed a mitigation against MFA fatigue attacks with their authenticator app.

In early 2024, a small percentage of Apple consumers experienced a MFA fatigue attack that was caused by a hacker that bypassed the rate limit and Captcha on Apple’s “Forgot Password” page.

References

  1. ^ "MFA Fatigue: Hackers' new favorite tactic in high-profile breaches". BleepingComputer. Retrieved 2023-01-26.
  2. Burt, Jeff. "Multi-factor authentication fatigue can blow open security". www.theregister.com. Retrieved 2023-01-26.
  3. Constantin, Lucian (2022-09-22). "Multi-factor authentication fatigue attacks are on the rise: How to defend against them". CSO Online. Retrieved 2023-01-26.
  4. Whittaker, Zack (2022-09-19). "How do you stop another Uber hack?". TechCrunch. Retrieved 2023-08-24.
  5. Hardcastle, Jessica Lyons (2022-09-19). "Uber explains how it was pwned this month, points finger at Lapsus$ gang". The Register. Retrieved 2023-08-24.
  6. Tung, Liam. "Microsoft Authenticator gains feature to thwart spam attacks on MFA". ZDNET. Retrieved 2023-01-26.

Further reading


Stub icon

This computer security article is a stub. You can help Misplaced Pages by expanding it.

Categories: