Cybersecurity
Don't Open the Door to the Attacker
How to Outsmart Unexpected MFA Notifications
How to protect yourself
1
Only confirm your own logins
Only confirm an MFA notification in the Microsoft Authenticator app if you started the login yourself.
2
Reject unexpected prompts
If you don't know why you received an MFA notification, don't confirm it, even if it keeps repeating.
3
Watch out for fake login pages
Never enter your password after clicking a link in an unexpected email. Always check the page address and be alert to typos or an unusual domain.
4
Protect your password
Don't use the same password for work and personal accounts.
5
Change your password immediately
If you have accidentally approved an unknown MFA notification or entered your password on a suspicious page, change your password immediately and contact the Service Desk straight away.
Ten warning signs
1
The sender's address doesn't match
The name is correct, but the domain after the @ sign is suspicious, for example ending in @micros0ft-support.com.
2
Pressure for a quick response
The sender uses words like "immediately", "final notice" and similar.
3
A request for your password or to log in
Never log in via a link in an email.
4
An unexpected financial request
Watch out for a changed account number or a payment request in the email.
5
Suspicious attachments
Never open documents with macros or attachments with .ZIP or .EXE extensions, and report them all to IT Security in the FIG/2 unit.
6
Strange language
The email may be written in poor Czech or have an unnatural tone and word order.
7
The context doesn't fit
If you are asked to confirm an order although you haven't ordered anything, it's best to report or ignore the email.
8
Unusual links
The email contains link shorteners (bit.ly) or foreign domains. You can check the real address by hovering your mouse over the link.
9
Branding inconsistencies
The logo in the email is blurred or has a different number of letters or different colours.
10
Request for discretion
The email contains phrases such as "don't tell anyone" or claims to be from "management".
You receive an MFA notification on your phone from the Microsoft Authenticator app asking you to confirm a login. Then another one arrives shortly after. And then another. If you're not logging in anywhere, this is not a normal system prompt. It could mean that someone is trying to gain access to your account.
Login credentials are among the most valuable targets for cyber attackers. Once they obtain a password to a company account, multi-factor authentication (MFA) presents a further obstacle. However, they sometimes don't try to bypass it technically. Instead, they rely on the human factor and wait to see if access is confirmed for them.
How the attack works
The first step is usually obtaining the password, for example through a phishing email or a fake login page. If the account is protected by MFA, the attacker then attempts to log in, which triggers an MFA notification to be sent to the user.
Sometimes the attacker sends it repeatedly. They rely on the user approving one of the prompts in a hurry, mistaking it for their own login, or confirming it just to stop further notifications from arriving.
A single such confirmation can allow the attacker to access the account, as well as emails, documents or other systems the account owner is authorised to use.
You're already familiar with the MFA card, as you use it to log in at work. The MFA notification works similarly, except the message asking for multi-factor authentication arrives on your mobile phone.
Uber already knows about it
A similar type of attack played a role in a major security incident at Uber in 2022. An attacker obtained an employee's login credentials and then repeatedly sent them MFA notifications. After one of the prompts was approved, the attacker managed to gain access to the company's internal environment.
The case shows that an attacker doesn't need to break multi-factor authentication in a complicated way. Sometimes it's enough to convince the user to approve the unwanted login themselves.
What should raise a red flag
An unexpected MFA notification can be the first sign of a compromised password and an ongoing attempt to take over your account. Be alert if you receive an MFA notification even though you're not logging in anywhere, or if you receive several within a short period of time. A notification at an unusual time, for example during your holiday, or an MFA notification from an unknown device or location, can also be suspicious. Another warning sign is if someone contacts you by phone or message asking you to confirm a login.
Tip
Always dismiss an unexpected MFA notification and report the event to the Service Desk. It could mean that an attacker has already obtained your login credentials and is trying to log in to your account. The quickest way to change your password is to reset it, which you can request through your supervisor or coordinator, or do directly via UMS Info in Information About Me. You can also ask the Service Desk to reset it, as it operates 24/7 and accepts requests via a web form, by phone on +420 326 817 777, or by email.
Cybersecurity