Security Alert: MFA Spamming Attacks Increase Cyber Claims
Coalition Incident Response, Inc. (CIR), a technical forensic and remediation firm and Coalition's affiliate, has observed an increase in multi-factor authentication (MFA) spamming attacks, also known as MFA fatigue or MFA bombing, leading to cyber insurance claims. MFA is a critical security control for many organizations, but it is susceptible to compromise via fatigue attacks, where threat actors overwhelm employees with nonstop authentication requests. As a result, users may accidentally accept a request or merely accept out of frustration from the high volume of alerts.
MFA spamming most often leads to business email compromise (BEC) cases. These BEC events can lead to the compromise or loss of various types of data and information, including intellectual property, critical business data, and personally identifiable information (PII). It can also lead to Funds Transfer Fraud (FTF) events where threat actors redirect and steal funds.