Some Apple users report being targeted in “MFA bombing” attacks, in which phishers inundate their devices with alerts to approve a password change or login
Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple's password reset feature.
Context & Ripple Effects
Apple-branded phishing had already been identified as a growing problem for macOS users in earlier coverage of Apple-themed phishing. This incident matters because it turns familiar account-security prompts into the pressure mechanism, rather than merely imitating an Apple message.
Related coverage later connected Apple account recovery to both forced Apple ID password resets across devices and voice-phishing abuse of Apple’s support line. That arc makes the recovery and approval flow itself a consequential attack surface.
First-order effects
- Targeted Apple customers may be pressured into approving a password change or login while their devices are overwhelmed with legitimate-looking prompts.
- Apple must assess whether its password-reset process can be triggered or repeated in a way that enables this harassment and phishing sequence.
Second-order effects
- Support and account-recovery teams face a harder distinction between genuine recovery activity and attacker-induced prompts, increasing the value of clearer recovery signals and abuse controls.
- The attack reinforces that MFA can be defeated through consent fatigue: Cloudflare’s earlier incident showed how hardware MFA keys blocked access after employees fell for SMS phishing, unlike approval flows that depend on a user choosing correctly under pressure.
Third-order effects
- If repeated-prompt attacks persist, authentication design will shift further from frequent user approvals toward rate-limited recovery flows and phishing-resistant factors.
- The broader security boundary moves beyond login itself: identity providers will be judged on whether their recovery and support channels can resist coordinated social engineering.
The trend: MFA bombing is part of a wider shift in phishing from stealing credentials outright to manipulating the account-recovery and approval systems meant to protect them.