Accessibility links
  • Skip to main content
News Icon NEWS FILTER
All News Security Education Videos Scams & Phishing Your Security Mobile Security Identity Theft Education Corporate Security
Search Icon SEARCH
 

Email Icon SUBSCRIBE TO WEEKLY NEWSLETTER
MFA Codes Bomb Your Apple Devices
Facebook   X   LinkedIn   Email

MFA Codes Bomb Your Apple Devices

September 29, 2024

You know that feeling when you’re busy and trying to focus on something and then BAM! You get a barrage of phone calls or emails, and it seems everyone is pulling you in one direction or the other. At some point, you just take action to get it all to stop so you can go back to your task. Attackers know this about us and there is an ongoing strategy that counts on you clicking a message away so you can continue. In this case, they claim you need to reset your Apple ID password and send a barrage of texts hoping you’ll just “allow” them to proceed in scamming you.

KrebsonSecurity investigated claims that several Apple users were getting “MFA bombed” with texts until they allowed them to send an MFA reset code. To the attackers’ credit, there was a “don’t allow” button as well, but with this and so many other attacks, they hope you’ll be in far too much of a rush to scroll down to find the “don’t allow.” In fact, even if you do take the time, it won’t stop the bombing and in fact, you may just get a “courtesy call” from the scam artist.

MFA bombing happens when you get inundated with messages with MFA codes. There are so many popups that you are worn down and click them away so you can get back to using your phone. In this case, they take it a step further. If you never click “allow,” they will actually call you (spoofing Apple’s phone number) and try to convince you that they are Apple Support trying to help. As is the case with a common Facebook Messenger attack, they will ask for a code you received after clicking the allow button. If you give it to them, they can reset your password and take over your phone number and Apple account. Considering all of the information that is attached to your Apple ID, that’s definitely not a positive thing.

The correct action for you is to hang up and call Apple Support directly, if in doubt. When a user tried to do just that, Apple was not able to say who may be calling, if anyone. However, they stressed that they will NOT call you unless you specifically request for them to do so.

According to some researchers, this attack is taking advantage of a flaw in Apple’s security. Unfortunately, there is nothing we can do to prevent this attack. Apple claims that enabling a recovery key in your settings will prevent anyone from sending a barrage of notifications. However, when it was tested by KrebsonSecurity, it did not turn out to be the case.

Just remember that if you are inundated with texts about anything, consider them very suspicious. After all, legitimate password reset MFA codes are not sent in a spam-like fashion.  So if it happens, it’s probably someone phishing you.

While it might seem obvious, when we get notifications like that and they are not expected, it's natural to panic a little bit and just click something. Instead, stop and take a second. Then reach back into your memory and if you didn’t ask to reset your password for your Apple ID, or for any account, it might be an attacker trying to wear you down. Then log into your account directly using a link you already know and find out if there really is a problem. Most of the time, your instincts are correct.


Your Data For Sale On The Dark Web And What You Can Do About It

Identity Theft

Your Data For Sale On The Dark Web And What You Can Do About It

As much as we love the convenience of our digital world, we know a hefty price tag can come with it. The world is full of bad actors whose goal is to get their hands on our sensitive, personally identifiable information, or PII. Should you find your PII is for sale on the dark web, it helps to know there are options for doing something about it, even if you think it’s too late. Just some of that hijacked PII can include passwords, email and physical addresses, Social Security numbers, financial accounts, and much more. READ FULL STORY

Spyware Pop-Up Danger – 4 Words NOT To Click

Scams & Phishing

Spyware Pop-Up Danger – 4 Words NOT To Click

When it comes to our personal online safety, sometimes knowing what NOT to do is as important as doing the smart thing. Avoiding trouble like spyware is crazy important, including knowing how not to download it. There are security basics we can all benefit from, and one of the following tips involves four little words NOT to click on with those annoying but potentially dangerous pop-ups. A security employee from McAfee shares the four words to avoid those bad pop-ups or risk downloading spyware. READ FULL STORY

Bootleg Apple Software Hides Cryptomining Malware On Macs

Your Security

Bootleg Apple Software Hides Cryptomining Malware On Macs

For those keeping up with technology news, it’s not often Macs make hacking headlines. And for those who are simply Mac lovers, it’s not wise to think hacks happen only to Androids since both are vulnerable. A recent finding linking bootleg Apple software, malware, and cryptomining is a lesson all users can learn from. After all, a successful attack on Macs can end up targeting Androids, too. Security researchers at Jamf Threat Labs found a bootleg version of Final Cut Pro Apple software hiding cryptomining malware. READ FULL STORY

Phone Scammers Use Big Tech As Lures

Mobile Security

Phone Scammers Use Big Tech As Lures

Ask a robocall recipient and they’ll tell you that robocalls are annoying and a waste of time. But the victim of a phone scam (vishing) will tell you it could mean losing a lot more than just time. Like email phishing, falling for a vishing scam can put you in danger of losing your identity, your money, and any other private information a criminal can get. So, what to do when the caller claims to be from a trusted business and has a legitimate reason to call? READ FULL STORY

Senior Safety Online – AARP’s Top Tips For Data Security

Identity Theft

Senior Safety Online – AARP’s Top Tips For Data Security

It’s widely known that seniors are a choice target for cybercriminals. In fact, they are the second most target age group for cybersecurity crimes. Thanks to a publication by AARP “My Online Privacy for Seniors,” this e-book offers ways this vulnerable population can be smarter about their online security. It offers basic steps and strategies for keeping PII secure. Below are some of the AARP’s top online tips for seniors, so share them with an older friend or loved one – they’ll thank you for it. READ FULL STORY








Close
Fraud News & Alerts!

Keep up with the latest cyber security news through our weekly Fraud News & Alerts updates. Each week you will receive an email containing the latest cyber security news, tips and breach notifications.



You're all set!

You will receive your first official security update email within the next week.

A welcome email has also just been sent to you. If you do not receive this email within the next few minutes, please check your Junk box or spam filter to confirm our emails are not being blocked.


 
Help  
Enter any word or words you like.        

The email newsletter will arrive from news@stickleyonsecurity.com


Loading
Please wait...