/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Some Apple users report being targeted in “MFA bombing” attacks, in which phishers inundate their devices with alerts to approve a password change or login

Several Apple customers recently reported being targeted in elaborate phishing attacks that involve what appears to be a bug in Apple's password reset feature.

Krebs on Security Brian Krebs

Context & Ripple Effects

Apple-branded phishing had already been identified as a growing problem for macOS users in earlier coverage of Apple-themed phishing. This incident matters because it turns familiar account-security prompts into the pressure mechanism, rather than merely imitating an Apple message.

Related coverage later connected Apple account recovery to both forced Apple ID password resets across devices and voice-phishing abuse of Apple’s support line. That arc makes the recovery and approval flow itself a consequential attack surface.

First-order effects

  • Targeted Apple customers may be pressured into approving a password change or login while their devices are overwhelmed with legitimate-looking prompts.
  • Apple must assess whether its password-reset process can be triggered or repeated in a way that enables this harassment and phishing sequence.

Second-order effects

  • Support and account-recovery teams face a harder distinction between genuine recovery activity and attacker-induced prompts, increasing the value of clearer recovery signals and abuse controls.
  • The attack reinforces that MFA can be defeated through consent fatigue: Cloudflare’s earlier incident showed how hardware MFA keys blocked access after employees fell for SMS phishing, unlike approval flows that depend on a user choosing correctly under pressure.

Third-order effects

  • If repeated-prompt attacks persist, authentication design will shift further from frequent user approvals toward rate-limited recovery flows and phishing-resistant factors.
  • The broader security boundary moves beyond login itself: identity providers will be judged on whether their recovery and support channels can resist coordinated social engineering.

The trend: MFA bombing is part of a wider shift in phishing from stealing credentials outright to manipulating the account-recovery and approval systems meant to protect them.

Discussion

  • @parth220_ Parth on x
    Last night, I was targeted for a sophisticated phishing attack on my Apple ID. This was a high effort concentrated attempt at me. Other founders are being targeted by the same group/attack, so I'm sharing what happened for visibility. 🧵 Here's how it went down:
  • @mattjay Matt Johansen on x
    @parth220_ Check this thread where @parth220_ faced 100+ notifications across his Apple devices, a classic sign of ‘push bombing’ Despite his vigilance, the fake support call he received knew disturbingly accurate personal details.