
Fake Install Guides and Helpdesk Calls Drive Attacks
This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…
The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA fatigue; Colonial Pipeline legacy VPN without MFA) and provides practical defensive steps like phishing-resistant MFA, tightening account recovery, and regularly reviewing authentication workflows.
Multifactor authentication is often treated as a near-guarantee of account security, but attackers have developed several real-world techniques to get around it. One method, known as MFA fatigue or push bombing, involves rapidly sending numerous authorization requests, typically via SMS push messages, until a user gives in and approves the request, granting access to an attacker. Attackers often pair this with social engineering, impersonating internal IT or security staff to create a false sense of trust and pressure the target into approving the login.
Other techniques target the authentication channel itself rather than the user's patience. SIM swapping works by convincing a telecom customer service employee that the attacker is the legitimate phone owner, redirecting SMS one-time codes to the attacker's device. Separately, attackers set up phony login pages or use real-time relays and man-in-the-middle proxies to intercept MFA codes as a user types them in. In some cases, attackers skip credentials and codes altogether by stealing session cookies or authentication tokens, since the authorization process has no way of knowing whether the current holder of that token ever legitimately authenticated.
These techniques succeed because they exploit trust and process gaps rather than breaking encryption. A flood of prompts wears down user attention, and a confident, urgent-sounding pretext from someone claiming to be IT reduces scrutiny. Telecom support processes can be manipulated through social engineering rather than technical exploitation. And because many websites don't enforce session inactivity limits, a stolen cookie can grant ongoing access without ever triggering another MFA challenge.
Organizations can reduce exposure by treating unexpected MFA prompts as a likely attack: employees should deny and report them rather than approve them to "make the alerts stop." Reducing reliance on SMS-based codes and strengthening account recovery and SIM-change processes closes off common bypass paths. Enforcing session timeouts and monitoring for cookie or token theft limits how much value an attacker gains from a captured session. Regularly reviewing authentication workflows, including how IT, service desk, and telecom support staff verify identity, helps ensure MFA delivers the protection it's meant to provide.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
MFA fatigue, also called push bombing or prompt bombing, is when an attacker rapidly sends numerous authorization requests until a user gives in and approves one, granting access.
Yes. Attackers can intercept session cookies or tokens after a user authenticates, and reuse that session to bypass MFA entirely since the system cannot verify whether the token holder legitimately authenticated.
An attacker convinces a telecom customer service employee that they are the legitimate phone owner, then redirects the victim's number to a new SIM so SMS one-time codes are delivered to the attacker instead.
Treat any MFA prompt they did not initiate as a potential attack, deny it, and report it immediately rather than approving it to make the alerts stop.
You know those random MFA pop‑ups on your phone? Attackers now spam those on purpose until you finally tap Approve. This is what hit Uber in 2022: nonstop prompts plus a fake ‘IT support’ call, saying, “Just approve one to stop the alerts.” One tap, and they’re in, MFA and all. And it’s not just push bombing. Fake login pages can grab your one-time codes in real time, SIM swaps can hijack your SMS, and stolen session cookies can skip MFA entirely. Your move: if you get an MFA prompt you didn’t start, hit Deny and report it to Security immediately, treat every unexpected prompt as an active attack.

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented…

Check Point reports that OpenAI’s ChatGPT became a top-10 most impersonated brand in Q2 2026 phishing. One observed example used a fake “ChatGPT Plus payment…

The “Pink” data extortion group is running a real-world voice phishing campaign targeting employees in Microsoft 365 / Entra ID environments. Callers…