Security attacks taking advantage of multi-factor authentication (MFA) push notification fatigue are increasing because MFA is working, Expel noted in its latest Quarterly Threat Report.
The findings are based on incidents identified by Expel’s security operations center during the third quarter of 2022. It found MFA and conditional access, which are often part of a zero-trust strategy, were configured for a majority (more than 80%) of the successful compromises, while attackers got in by tricking the legitimate users to accept the MFA request.
On the other hand, around half of the business application compromises (BAC) in the quarter were stopped by MFA or conditional access policies, the report found.
“We’ve seen an increase in MFA push notification fatigue attacks. Why? Because they work,” noted Ben Brigida, director of SOC operations at Expel. “More organizations are turning to cloud access identity providers for single sign-on capabilities. Attackers know that if they can get their hands on credentials for these platforms they’ll get access to critical business applications.”
So, “the attacker simply wore down the user with MFA requests until they finally approved,” he added.
To address this tactic or ease MFA fatigue, Brigida recommended organizations replace the push notification methods with a PIN or FIDO-compliant MFA solutions or switch. This can control push notifications using number matching that requires users to enter numbers from the identity platform into their MFA app to approve the authentication request.
Identity-Based Attacks RiseThe growing MFA attack trend is in line with a recent Okta-sourced report.
Expel found 60% of the incidents analyzed in the report were identity-based, which was up slightly from last quarter.
“We saw this trending last quarter and we’re seeing it again: identity-based attacks are increasing,” Brigida said. “These attacks began with an initial lead from an integration with a cloud infrastructure or identity provider.”
The vendor also investigated phishing attacks and found that 57% of the phishing emails had blank subject lines. And some forms of "invoice," "order confirmation," "payment," "request," and "document" were often used.
“MFA, ideally with phish-resistant FIDO security keys, will significantly reduce the risks associated with credential theft through phishing,” he said. “Orgs can also consider deploying a secure email gateway to monitor incoming and outgoing emails for signs of an attack.”
“Lastly, education goes a long way in helping ensure that employees don’t fall for phishing attempts, especially when that training is tailored to business units,” Brigida added.
Comments