Close Menu
    What's Hot

    Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules

    Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue

    Mette Frederiksen Forms New Government in Denmark

    Facebook X (Twitter) Instagram
    Trending
    • Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules
    • Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue
    • Mette Frederiksen Forms New Government in Denmark
    • Trump Stands to Gain a Key Ally in Colombia’s Upcoming Election
    • Anthropic’s browser agent got hijacked 31.5% of the time before safeguards engaged
    • French Open: Aryna Sabalenka beats Naomi Osaka to reach quarter-finals at Roland-Garros | Tennis News
    • England vs India: Danni Wyatt-Hodge expecting ‘fireworks’ from struggling opening partner in T20 series decider | Cricket News
    • The Google Pixel Watch 5 may have been spoiled by… the creator of Borderlands
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Why Your Second Factor Isn’t Saving You

    adminBy adminMay 26, 2026No Comments5 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Why Your Second Factor Isn’t Saving You
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Why Your Second Factor Isn’t Saving You

    Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn’t log in without the second factor. While that logic was sound, attackers have now figured out that they don’t need to steal the second factor: they just need the user to hand it over.

    If your workforce authenticates with push-based MFA, this attack is a live threat to your organization today. Tools like Specops Secure Access are built specifically to close that gap, but before getting into the fix, it’s worth understanding how this technique works.

    How MFA prompt bombing works

    The attack requires three key elements to work:

    • Valid account credentials, usually sourced from breached password dumps on the dark web
    • A login portal that uses push-based MFA (such as a VPN, Microsoft 365, Okta, or Duo)
    • A victim who is alerted every time the attacker tries the login

    Attackers repeatedly trigger the prompt, attempting to trick the target or wear them down to approve the request. Sometimes, attackers will pair prompt bombing with a vishing call pretending to be from IT, where they will try to socially engineer the target. The danger is that these methods only need to work once.

    If the prompt is approved, the attacker is logged in as that user. Security systems typically won’t be alerted, as the login looks entirely legitimate.

    The Cisco breach

    The 2022 Cisco breach is a key example of how effective this technique is against even mature security programs. An attacker linked to the Yanluowang ransomware group compromised a Cisco employee’s personal Google account, which was syncing browser-stored credentials, including the employee’s Cisco VPN password.

    From there, the attacker pushed MFA prompts to the employee’s phone. That initially didn’t work, so they began using vishing calls posing as trusted support organizations, speaking in various accents, and eventually convincing the employee to accept a push notification.

    Once accepted, the attacker had VPN access as the employee. They then enrolled their own devices for MFA to maintain persistence, escalated to administrative privileges, reached Citrix servers and domain controllers, and exfiltrated around 2.8GB of data before being evicted. The fact that prompt bombing worked against a company like Cisco, which is far from having a weak security posture, highlights just how dangerous and effective the attack has become.

    Why push MFA doesn’t eliminate risk

    The issue with push-based MFA is that users are asked to approve or deny a login with very little to go on. There’s no clear indication of where the request originated, what device is being used, or whether the login attempt was initiated by the user at all. In isolation, that might be manageable. But when prompts start arriving repeatedly, it’s easy to assume something’s misfiring rather than recognizing it as a potential attack.

    If that’s paired with a well-timed phone call from someone posing as IT support, the situation becomes even harder to assess. At that point, the user isn’t acting carelessly, but responding to a scenario designed to feel routine and legitimate, using credentials the attacker already has.

    3 ways organizations can prevent prompt bombing

    1. Use fatigue and phishing-resistant MFA factors

    Push notifications are the weakest common form of MFA. Phishing-resistant factors such as FIDO2 security keys, hardware tokens like YubiKey, or number-matching codes from authenticator apps are harder to abuse.

    Specops Secure Access supports more than 15 identity providers and includes these fatigue-resistant options for Windows logon, RDP, and VPN connections, so organizations can retire push-only MFA for high-risk access points.

    Specops Secure Access

    2. Block compromised passwords at the source

    Prompt bombing is only made possible when the attacker already has a valid password. Scanning Active Directory (AD) continuously against a live database of breached passwords, and forcing a reset when a match appears, removes the fuel for the attack. Relying on default AD password policies won’t catch reused, incremental, or breached passwords. If you don’t know where you stand today, Specops Password Auditor is a free, read-only scan of your AD that flags vulnerabilities like compromised passwords or inactive admin accounts.

    Specops Password Auditor

    3. Add risk signals to the login

    Conditional access policies that factor in geography, device posture, and login times can block or step up authentication before a prompt is ever sent to the user’s phone. This reduces reliance on user behaviour alone and introduces real-time context to stop suspicious logins before they escalate into successful account compromise.

    MFA still matters

    MFA prompt bombing isn’t a reason to move away from MFA, but it does highlight where some factors fall short. When approval requests can be triggered repeatedly with no meaningful context, the control becomes easier to influence than intended.

    If push is still your default second factor, it’s worth revisiting that decision. Number matching or phishing-resistant methods strengthen the MFA method itself, while scanning for compromised passwords limits the risk of attackers possessing the first authentication step. If you’re looking to evolve your identity security with more robust MFA, talk to Specops.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Factor isnt saving
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleTaking Women Farmers Seriously by Ruth Khasaya Oniang’o & Peter Kelly
    Next Article Uber president says AI spending is getting ‘harder to justify’
    admin
    • Website

    Related Posts

    Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

    June 1, 2026

    Water access is now a risk factor in SpaceX’s IPO

    June 1, 2026

    Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts – Krebs on Security

    June 1, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Demonstrators Cannot Be Forced to Take Down ‘86-47’ Flag, Judge Rules

    Trump Says Israel, Hezbollah to Halt Attacks as Iran Talks Continue

    Mette Frederiksen Forms New Government in Denmark

    Trump Stands to Gain a Key Ally in Colombia’s Upcoming Election

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by