Root Causes 335: When MFA Is Not MFA

29/09/2023 9 min
Root Causes 335: When MFA Is Not MFA

Listen "Root Causes 335: When MFA Is Not MFA"

Episode Synopsis

In this episode we describe a social engineering attack to steal a one-time password (OTP) to enable unauthorized access. This incident further exploited a cloud backup feature to extend the scope of the breach. We explain.