"Apple Users Beware: MFA Bombing and Phishing Attacks on the Rise"

TL;DR Summary
Apple users are being targeted in an advanced phishing attack that exploits a potential bug in Apple's password reset feature, bombarding them with endless password change notifications in an attempt to trick them into approving the change. Attackers are able to lock users out of their accounts if the request is approved, and they may also make phone calls pretending to be Apple support to obtain one-time password reset codes. The attack seems to exploit a bug in Apple's forgotten password page, and affected users should be cautious and avoid clicking "Allow" on any suspicious requests.
- Warning: Apple Users Targeted in Advanced Phishing Attack Involving Password Reset Requests MacRumors
- Recent 'MFA Bombing' Attacks Targeting Apple Users – Krebs on Security Krebs on Security
- An attack method to steal Apple ID by continuously sending identity verification notifications to iPhone is reported GIGAZINE(ギガジン)
- Apple Users Get Hit by MFA Bombing Attacks That Exploit System Glitch The Mac Observer
- Beware! a Bug in Apple’s Password Reset Feature Is Leading to Phishing Attacks Beebom
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
5 min
vs 6 min read
Condensed
91%
1,080 → 96 words
Want the full story? Read the original article
Read on MacRumors