By NHI Mgmt Group Editorial TeamDomain: Breaches & IncidentsSource: AnomaliPublished October 7, 2025

TL;DR: Medusa attempted to recruit a BBC reporter as an insider with a 15% to 25% payout offer, then escalated to MFA bombing when persuasion failed, while also claiming prior success against healthcare and emergency service providers, according to Anomali. The pattern shows that identity controls must cover social engineering, authentication fatigue, and employee reporting pathways, not just access policy.


At a glance

What this is: Anomali’s cyber watch highlights a ransomware crew using insider recruitment and MFA bombing to probe identity weak points.

Why it matters: Identity teams need to treat user coercion and authentication prompt abuse as access-risk events that can bypass technical controls if reporting, monitoring, and response are weak.

By the numbers:

👉 Read Anomali’s Cyber Watch analysis of insider recruitment and MFA bombing


Context

Insider recruitment is a governance failure as much as a social engineering tactic. When attackers move from phishing to direct persuasion, they are testing whether the organisation can detect pressure on a person before that pressure becomes a security incident, and that challenge sits squarely inside human identity and access governance.

In this case, the identity risk was not a compromised machine identity or a leaked secret. It was the attempt to turn a legitimate employee into an access path, then increase pressure through repeated MFA prompts when the first approach failed. That is a typical escalation pattern, not an edge case.

The primary lesson for IAM and PAM teams is that authentication controls alone do not absorb insider-risk scenarios. Organisations need visibility into anomalous login prompt patterns, fast escalation channels for staff who are targeted, and access governance that assumes coercion can precede compromise.


Key questions

Q: How should security teams handle insider recruitment attempts before access is gained?

A: Treat the approach itself as a security event, not a private employee matter. Give staff a fast reporting path, preserve chat or message evidence, and trigger an identity review for the targeted account. The goal is to intervene before the attacker turns social pressure into a usable login, approval, or privileged session.

Q: Why do repeated MFA prompts create account takeover risk?

A: Repeated prompts work because they pressure the user into a fast decision. The attacker is not bypassing the factor directly. They are overwhelming the person behind it until one approval completes the session. That is why human vigilance alone is not a durable control and why organisations need context-aware step-up policies and stronger factors for higher-risk access.

Q: What breaks when organisations treat insider risk and IAM as separate programmes?

A: They miss the transition from persuasion to access abuse. An employee who is being targeted may become the access path if login events are not correlated with coercion reports, and response ownership becomes fragmented. That delay gives attackers time to turn a human target into a security control failure.

Q: Who is accountable when a user is pressured into approving fraudulent access?

A: Accountability sits with the organisation’s identity, security, and people-risk functions together. IAM owns the control plane, security owns detection and response, and HR or employee relations may need to support the human side. Frameworks that emphasise access assurance and auditability apply here because the event crosses technical and human domains.


Technical breakdown

Insider recruitment as an access pathway

Insider recruitment works because attackers are trying to shortcut perimeter controls by persuading a legitimate user to create access on their behalf. The critical detail is that the employee already has a trusted identity, so the attacker does not need to defeat authentication in the usual way. Instead, they test whether money, fear, or pressure can override policy and process. In practice, this blends social engineering with identity abuse, which is why HR, security operations, and IAM governance all have to see the event as the same problem.

Practical implication: treat employee-targeted recruitment attempts as identity incidents and route them into the same response path as suspicious login activity.

MFA bombing and authentication fatigue

MFA bombing, also called push fatigue, overloads the user with repeated approval prompts until they accept one by mistake or simply to make the notifications stop. The technique does not break the authenticator itself. It exploits human response under pressure and the assumption that a user will notice and reject every prompt. That makes it a control bypass on the human side of MFA rather than a protocol failure, and it is especially effective when the attacker already knows the target account is active and valuable.

Practical implication: reduce repetitive push prompts, add number matching or phishing-resistant MFA, and watch for clustered approval requests from the same account.

Why insider risk and authentication risk are linked

Insider-risk programmes often focus on malicious employees or departing staff, while IAM programmes focus on login assurance. This article shows those are not separate problems. A targeted insider approach can lead directly into authentication abuse when persuasion does not work, and the same user may become both the initial target and the access vector. That linkage matters because the right signal is not only who logged in, but who is being pressured and whether the organisation can intervene before an approval is granted.

Practical implication: combine user-reporting channels, IAM telemetry, and SOC triage so coercion attempts and authentication abuse are handled together.


Threat narrative

Attacker objective: The attacker aimed to turn a legitimate employee into an access foothold for ransomware-linked intrusion.

  1. Entry began with direct contact on Signal, where the actor attempted to recruit a BBC reporter as an insider by offering a share of ransom proceeds.
  2. Escalation followed when persuasion failed, with repeated MFA-bombing prompts used to pressure the target into approving access.
  3. Impact would have been unauthorized access to internal systems that could support ransomware operations and ransom leverage.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Identity governance fails when it assumes attack paths begin with technical compromise. This case shows that an access event can start with persuasion, not malware, and then shift into authentication abuse when the first approach fails. For identity teams, the practical lesson is that user coercion belongs in the same risk model as credential theft and privilege misuse.

Authentication fatigue is a control weakness, not just a user experience issue. Repeated MFA prompts turn trust in the login flow into an exploitable pattern, especially when the attacker has already selected a high-value account. The governance gap is the assumption that a valid user will always act as a reliable security control. Practitioners need to treat prompt abuse as part of the identity attack surface.

Insider-risk telemetry and IAM telemetry need to converge. The article’s value is not only in the specific campaign but in the connection between human pressure and account abuse. Security teams that monitor only malware or only login events will miss the transition point where coercion becomes access. The result is slower response and weaker containment.

Human identity programmes need incident paths for coercion, not just policy acknowledgements. Annual training does little when an attacker is actively engaging a person in real time and escalating pressure through authentication prompts. The field should treat targeted recruitment as a live identity event with reporting, triage, and rapid account review attached to it. That is the difference between awareness and control.

Insider recruitment and MFA bombing are the same story at different layers. The first is a social layer attempt to open the door, and the second is a control-layer attempt to force the door open once persuasion fails. Organisations that separate those layers operationally create delay, and delay is what these campaigns depend on. The implication is tighter linkage between human reporting, access monitoring, and response ownership.

From our research:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
  • That gap matters because identity risk often persists long after the first detection, as shown in our 52 NHI Breaches Report and related lifecycle analysis.

What this signals

Targeted insider recruitment should change how teams think about identity monitoring. The practical shift is toward combining employee-reporting workflows, authentication telemetry, and access review into one operating model, because the attack path can begin with a conversation and end with privilege abuse.

Coercion-aware identity governance: this is the control gap that many mature programmes still miss. If your MFA programme only measures successful and failed logins, you may be blind to the repeated pressure that precedes a mistake, so a user-facing reporting channel becomes part of identity defence rather than an HR side issue.

The broader lesson for IAM and PAM leaders is that access assurance now depends on human resilience as much as credential integrity. Teams should expect more attempts to convert legitimate users into access paths and should wire that assumption into incident response, privileged access review, and training design.


For practitioners

  • Build a coercion-reporting path for targeted staff Create a simple, well-known process for employees who are approached by criminals, including direct reporting to security and HR, immediate account review, and a no-blame intake process.
  • Harden MFA against prompt abuse Move high-risk accounts to phishing-resistant MFA, add number matching or approval context, and alert on repeated prompts in a short window from the same user or device.
  • Correlate insider-risk and IAM signals Join suspicious contact reports, authentication anomalies, and access to sensitive systems so a targeted employee can be triaged before the attacker gains a usable foothold.
  • Review privileged accounts for coercion exposure Identify roles where a single approval or login could unlock administrative reach, then require stronger step-up checks and faster intervention paths for those identities.

Key takeaways

  • Medusa’s attempt to recruit a BBC reporter shows that insider pressure and authentication abuse are now part of the same identity threat chain.
  • The attack pattern relies on repeated MFA prompts and human fatigue, not on breaking the authentication technology itself.
  • Identity teams need coercion reporting, phishing-resistant MFA, and correlated monitoring to stop a person being turned into an access path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1Identity proofing and credential abuse are central to the incident pattern.
NIST SP 800-53 Rev 5IA-2Authentication failures and repeated prompts point to weak assurance controls.
OWASP Non-Human Identity Top 10NHI-08The incident illustrates identity abuse through access pressure and prompt fatigue.
NIST Zero Trust (SP 800-207)3.0Zero Trust assumptions fail if a trusted user can be manipulated into approving access.

Apply Zero Trust verification to high-value accounts and reduce reliance on user approval alone.


Key terms

  • Mfa Bombing: A social engineering tactic that overwhelms a user with repeated authentication prompts until they approve one by mistake or out of frustration. It does not usually defeat the authenticator itself. Instead, it exploits human behaviour and weak notification design to convert a legitimate login flow into an access bypass.
  • Insider Recruitment: The attempt to turn a legitimate employee, contractor, or partner into an access facilitator for criminal activity. The recruit may be asked to share credentials, approve a login, or use their own trusted access. In identity governance terms, it is a coercion-driven pathway into authorised systems.
  • Coercion-Aware Identity Governance: An identity governance approach that treats pressure on users as a security event, not only a people issue. It combines reporting, monitoring, and response so that targeted employees can be protected before their account becomes a breach vector. This is especially important where privileged or sensitive access is involved.
  • Authentication fatigue: A broader state in which repeated security checks cause users to stop treating authentication as a meaningful decision. It is a governance problem as much as a usability issue, because control effectiveness depends on sustained human judgement, not just policy enforcement.

What's in the full analysis

Anomali's full post covers the operational detail this article intentionally leaves for the source:

  • The original campaign timeline and threat actor notes around the BBC reporter recruitment attempt.
  • The article’s MITRE ATT&CK mapping for MFA request generation and related tradecraft.
  • Additional Anomali Cyber Watch items from the same issue, including Phantom Taurus and MatrixPDF context.
  • The broader threat monitoring context that security teams can use to compare this incident with other active campaigns.

👉 The full Anomali post adds the campaign context, actor commentary, and related threat updates.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM, PAM, or NHI governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org