Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Insider recruitment and MFA bombing: what identity teams need to watch


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Medusa attempted to recruit a BBC reporter as an insider with a 15% to 25% payout offer, then escalated to MFA bombing when persuasion failed, while also claiming prior success against healthcare and emergency service providers, according to Anomali. The pattern shows that identity controls must cover social engineering, authentication fatigue, and employee reporting pathways, not just access policy.

NHIMG editorial — based on content published by Anomali: Anomali Cyber Watch on insider recruitment, MFA bombing, and related threat activity

By the numbers:

Questions worth separating out

Q: How should security teams handle insider recruitment attempts before access is gained?

A: Treat the approach itself as a security event, not a private employee matter.

Q: Why do repeated MFA prompts create account takeover risk?

A: Repeated prompts work because they pressure the user into a fast decision.

Q: What breaks when organisations treat insider risk and IAM as separate programmes?

A: They miss the transition from persuasion to access abuse.

Practitioner guidance

  • Build a coercion-reporting path for targeted staff Create a simple, well-known process for employees who are approached by criminals, including direct reporting to security and HR, immediate account review, and a no-blame intake process.
  • Harden MFA against prompt abuse Move high-risk accounts to phishing-resistant MFA, add number matching or approval context, and alert on repeated prompts in a short window from the same user or device.
  • Correlate insider-risk and IAM signals Join suspicious contact reports, authentication anomalies, and access to sensitive systems so a targeted employee can be triaged before the attacker gains a usable foothold.

What's in the full analysis

Anomali's full post covers the operational detail this article intentionally leaves for the source:

  • The original campaign timeline and threat actor notes around the BBC reporter recruitment attempt.
  • The article’s MITRE ATT&CK mapping for MFA request generation and related tradecraft.
  • Additional Anomali Cyber Watch items from the same issue, including Phantom Taurus and MatrixPDF context.
  • The broader threat monitoring context that security teams can use to compare this incident with other active campaigns.

👉 Read Anomali’s Cyber Watch analysis of insider recruitment and MFA bombing →

Insider recruitment and MFA bombing: what identity teams need to watch?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Identity governance fails when it assumes attack paths begin with technical compromise. This case shows that an access event can start with persuasion, not malware, and then shift into authentication abuse when the first approach fails. For identity teams, the practical lesson is that user coercion belongs in the same risk model as credential theft and privilege misuse.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.

A question worth separating out:

Q: Who is accountable when a user is pressured into approving fraudulent access?

A: Accountability sits with the organisation’s identity, security, and people-risk functions together. IAM owns the control plane, security owns detection and response, and HR or employee relations may need to support the human side. Frameworks that emphasise access assurance and auditability apply here because the event crosses technical and human domains.

👉 Read our full editorial: Insider recruitment and MFA bombing raise identity risk stakes



   
ReplyQuote
Share: