Ale dirèk nan kontni an

MFA Phishing and Adversary-in-the-Middle Attack Response

Traditional Multi-Factor Authentication (MFA) via SMS text messages, one-time passcode (OTP) authenticator apps, or push notifications can be bypassed by sophisticated Adversary-in-the-Middle (AitM) phishing kits and MFA fatigue attacks.

AitM reverse proxies proxy live login traffic between victims and legitimate service providers, capturing user passwords and active session cookies simultaneously.

Recognizing AitM Phishing and MFA Fatigue Attacks

  • Domain Mis-match: The website interface looks identical to Microsoft 365, Google, or bank portals, but the browser address bar displays an unfamiliar domain name or typosquatted URL.
  • Repeated MFA Push Bombing: Receiving dozens of unprompted 2FA push notification approval requests on your phone in rapid succession (MFA fatigue attack designed to trick you into approving).
  • Session Hijacking Without Password Alerts: Unauthorized account access occurring without receiving password reset notifications, caused by stolen session cookies.

Immediate Emergency Response Steps

  1. Do Not Approve Unsolicited Push Prompts: Reject all push notifications you did not personally trigger.
  2. Terminate All Active Sessions Immediately:
  3. Log into your account security settings from a known clean device.
  4. Click Sign out of all locations, Revoke all active sessions, or Revoke trusted devices. This invalidates stolen session cookies instantly.
  5. Change Account Passwords: Update passwords for the compromised account and any other accounts sharing the same password.
  6. Audit Account Recovery Options: Inspect registered phone numbers, backup email addresses, and connected third-party OAuth app authorizations. Remove unfamiliar entries added by attackers.
  7. Report to IT or Security Teams: If corporate or organization accounts are involved, notify your IT security department immediately to block compromised session tokens tenant-wide.

Transitioning to Phishing-Resistant MFA (Passkeys and FIDO2)

  • Upgrade to FIDO2 / WebAuthn Passkeys: Use hardware security keys (such as YubiKey, Titan Security Key) or device-bound passkeys (Apple Keychain, Windows Hello).
  • Why Passkeys Block AitM Phishing: FIDO2 security keys bind authentication strictly to the verified origin domain in the browser address bar. Even if an attacker tricks you into entering credentials on a fake site, the security key will refuse to output authentication tokens to unverified domains.