Multi-Factor Authentication (MFA) is commonly used to protect your information online. However, MFA is not impenetrable from Social Engineering
If a password is compromised, hackers can deploy several tactics to get around any MFA protection.
The information in this blog has been sourced using The Hackers News. You can read the full story here
Adversary-in-the-middle (AITM) attacks from Social Engineering
An AITM attack involves “deceiving users into believing they’re logging into a genuine network, application, or website.”
Through this hack, people can unwittingly give information to Cybercriminals.
An example of this is a spear-phishing email that arrives in an employee’s inbox.
MFA prompt bombing
This attack involves push notifications in modern authentication apps. After hackers access a password, attackers try to use the password to trigger the MFA prompt for the compromised account.
If the user inputs their details into the MFA prompt, the hackers will gain full access to the account.
Service desk attacks from Social Engineering
Hackers access helpdesks by “feigning password forgetfulness and gaining access through phone calls.”
If the proper verification checks aren’t in place, hackers may be granted access to an organisational environment.
Another way is to “exploit recovery settings and backup procedures by manipulating service desks to circumvent MFA.”
An example of this is when hackers contact a service desk claiming their phone is not functioning or is lost, then request a new account which is controlled by an attacker-controlled MFA authentication device. This will allow the hackers to gain control.
SIM swapping
This technique involves Cybercriminals deceiving “service providers into transferring a target’s services to a SIM card under their control.”
The hackers can then effectively take over the target’s mobile phone service and phone number, letting them intercept MFA prompts and gain full access to accounts.
When businesses choose a new cloud phone system, the conversation usually starts with features. Can staff make and receive calls from their mobiles? Does
For many UK businesses, the PSTN switch-off still feels like a 2027 problem. The deadline is 31 January 2027, so it can be tempting
If your PSTN migration plan starts with buying a new phone system, you could be missing the bigger picture. The UK’s Public Switched Telephone
AI adoption is picking up fast across UK businesses. So is the number of companies who buy a tool, roll it out, and quietly
Most AI conversations start in the wrong place. A vendor pitches a tool. A demo looks impressive. A budget gets signed off. Then, months
AI is everywhere. But where should your business actually start? If you’ve looked at AI recently, you’ve probably been overwhelmed. Every week there’s a
Most business owners think they know what technology their teams use. Microsoft 365. Teams. A CRM. Job done. Then someone mentions they’re sharing files
The UK’s traditional phone network is being switched off for good. By 31 January 2027, BT will retire the Public Switched Telephone Network (PSTN),
Hybrid working is no longer a temporary adjustment for UK businesses. For many SMEs, it has become the default way of operating. The
If every member of your team spends 30 minutes a day on tasks that should take five (re-entering data, waiting for slow systems, copying
