Users Duped into Enabling Device Access Due to Overload of Push Notifications

This article has been indexed from

CySecurity News – Latest Information Security and Hacking Incidents

 

Malicious hackers are initiating a new wave of ‘MFA fatigue attacks,’ in which they bombard victims with 2FA push alerts in an attempt to mislead them into authenticating their login attempts. 
According to GoSecure experts, who have warned that attacks that take advantage of human behaviour to get access to devices are on the upswing. Adversaries employ multi-factor authentication (MFA) fatigue to bombard a user’s authentication app with push notifications in the hopes that they will accept and so allow an attacker to obtain access to an account or device. GoSecure described the assault as “simple” in a blog post earlier this week, noting that “it only requires the attacker to manually, or even automatically, send repeated push notifications while trying to log into the victim’s account”. 
Further, it added, “Once the attacker obtains valid credentials, they will perform the push notification spamming repeatedly until the user approves the login attempt and lets the attacker gain access to the account. This usually happens because the user is distracted or overwhelmed by the notifications and, in some cases, it can be misinterpreted as a bug or confused with other legitimate authentication requests.” 
The attack is exceptionally effective, according to GoSecure, not because of the technology involved, but because it exploits the human component through social engineering. 
Researchers wrote, “Many MFA users are

[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.

Read the original article: