All news
Security
17 September 2024

MFA is not enough on its own: token theft and prompt bombing

Attackers increasingly bypass multi-factor authentication by stealing session cookies or wearing users down with repeated prompts.

What this means for your business

An account with MFA can still be taken over. The follow-on is usually invoice fraud aimed at your customers.

Multi-factor authentication remains the highest-value security control a small business can turn on. It is also no longer a complete answer. Two techniques are now routine:

Adversary-in-the-middle phishing. A convincing fake login page relays your credentials and MFA code to the real site in real time, then steals the resulting session cookie. The attacker is now signed in as you, without needing your password again.

Prompt bombing. Repeated push notifications at 2am until someone taps approve to make it stop.

What we see afterwards

Almost always the same thing: mailbox rules created to hide replies, then a genuine-looking email to a customer with new bank details. The money goes and it rarely comes back.

What actually helps

  • Number matching rather than simple approve/deny prompts.
  • Conditional access limiting sign-in to expected locations and compliant devices.
  • Alerting on new mailbox rules and impossible-travel sign-ins. This is how you catch it in hours rather than weeks.
  • A payment process that doesn't rely on email. Any change of bank details gets verified by phone on a previously known number, no exceptions.
  • Passkeys or hardware keys for the accounts that matter most.

We monitor for these signals on the tenants we manage and have a compromise remediation process ready to run when one trips.

Worried this could affect you?

Cyber Essentials is the quickest way for a small business to close the gaps attackers use most.

See Cyber Essentials

Not sure how exposed you are?

Twenty minutes on a call is usually enough to tell you.