How MFA can fail organizations in a phishing attack
One expert points to phishing-resistant MFA as the way forward.
• 3 min read
If you’re trusting all of your organization’s cybersecurity to multifactor authentication (MFA), we have bad news for you: Attackers are getting much better at sidestepping it.
In a new report, identity and access management company Okta found that cyberattackers are using a new phishing kit to bypass MFA and obtain credentials via vishing attacks. Targets of potential attacks could include customers of Salesforce Identity, Microsoft Entra, and Okta itself.
According to the report, Okta obtained an inside view of this kit, “Work Panel,” which it described as a “multi-tenant platform” with tools for setting up new phishing domains, setting up phishing sites, and cloning targets.
Method of attack. This particular phishing attack is designed to mimic the sign-on experience from an identity provider.
Brett Winterford, VP of Okta Threat Intelligence, said attackers will focus on an organization after an employee has just joined, then call pretending to be someone from the help desk.
Attackers will utilize social engineering to convince a potential victim to sign into the faked identity provider portal using their normal credentials. After that, a loading screen appears and freezes in place while the attacker uses the legitimate credentials that the targeted user provides via the browser to access the system.
When MFA prompts the user, Winterford said, the attacker will inform the victim to respond to the (legitimate) push challenge so the attacker can proceed into the system.
Different MFAs for different folks. Winterford said that his team is now seeing more IT professionals choosing phishing-resistant authentication, which relies on a cryptographic binding between the user’s browser and the service they’re signing into. He also suggested that an organization set policies requiring the use of those authenticators to access resources, applications, and sensitive data.
Some vendors are able to provide phishing-resistant MFA, but IT teams are responsible for configuring them appropriately.
“Beyond that, it’s about establishing and really sticking to a process in the organization for, ‘How do I verify the identity of someone who calls me, claiming to be from the help desk?’” Winterford said. “The best thing you can do is make sure that there is one way in which they can expect to hear from the help desk if it comes through any other channel, through any other means, that they are going to be suspicious.”
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.
About the author
Caroline Nihill
Caroline Nihill is a reporter for IT Brew who primarily covers cybersecurity and the way that IT teams operate within market trends and challenges.
Top insights for IT pros
From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.
By subscribing, you accept our Terms & Privacy Policy.