WHAT IS MFA FATIGUE AND HOW CAN YOU PREVENT IT?

October 11, 2022

Credential compromise is one of the top causes of network security breaches, prompting many organisations to implement multi-factor authentication (MFA).

However, attackers are now finding ways around MFA.


SMS-based MFA, where users receive a MFA code via text message, has been proven to be insecure and many service providers have replaced it with alternatives. One of the most popular alternatives is 'push notifications' which are displayed to the user via an authenticator app.


However, recently there has been an increase in attacks that rely on a method known as MFA fatigue.


Attackers have now discovered that spamming an employee with MFA authorisation requests until they become so annoyed that they approve the request can be a very effective way of bypassing the additional layer of security that MFA is there to provide.


This method was used in the recent cyber attacks against Cisco and Uber. In the Uber attack, the criminals increased their chances of success by combining it with social engineering. They contacted the employee on WhatsApp, claiming to be a member of the IT team and instructing them to approve the login to get the MFA notifications to stop.


Employee training is always important for mitigating the risk of any cyber attack including MFA fatigue attacks. Employees need to be aware of such attacks and should be instructed to notify the organisation’s IT or security team if they receive many push notifications. They should also be aware that messages or phone calls allegedly coming from their IT department could actually originate from the attacker. One of these issues - a flaw in Apple's web browser technology, is being actively exploited by attackers.

SHARE


April 23, 2025
At Integrity IT, part of the Eco group of businesses, we believe that when you invest in people, you build a stronger business. That’s why we’re proud to share two well-earned internal promotions that reflect the continued growth and evolution of our team.
April 23, 2025
On 21/04/2025, Marks and Spencer (M&S) confirmed it was managing a cyber incident that disrupted contactless payments and delayed online order collections.
By Eddie Black February 19, 2024
INTEGRITY IT Solutions has strengthened its team following a successful restructuring of the business.
Leading IT specialists Integrity IT Solutions are supporting schools to achieve faster broadband.
By Eddie Black January 19, 2024
A LEADING IT company is offering schools and colleges a free review of their broadband connectivity to help them achieve targets for faster internet speeds as outlined in the latest Government’s guidelines.
By Eddie Black June 1, 2023
With ever-increasing pressures on businesses to achieve net zero, Gary Robertson, from EcoGoZero, explains why collaboration is key.
SHOW MORE