Dear UAH Faculty, Staff, and Students:
There is an increasing security threat to UAH accounts known as “MFA fatigue.” While our use of Duo Multi-factor Authentication (MFA) remains a crucial defense for your account, understanding this attack method is essential to keeping our systems secure.
What Is MFA Fatigue?
MFA fatigue occurs when an attacker, who has already obtained your username and password, floods your device with multiple MFA push notifications. Their goal is to frustrate you into approving a request just to stop the notifications. If you click “Approve” for a request you did not initiate, you are unknowingly granting an attacker access to your account and everything it can access, including your email, data, and UAH systems.
How to Protect Yourself
- Do Not Approve Unknown Requests: Never approve a push notification that you did not personally trigger. Instead, tap "Deny" or "No, it's not me.”
- Report Fraudulent Activity: If you receive an unexpected notification, use the Duo app to report it as fraudulent. This is vital, as simply ignoring the prompt does not solve the underlying issue.
- Reset Your Password Immediately: If you are the target of unexpected MFA push notifications, it is a strong indicator that an attacker has your current UAH password. Please change your password immediately to secure your account using https://reset.uah.edu and let the OIT Help Desk know if assistance is needed.
Your vigilance is our strongest defense against these types of attacks. Thank you for doing your part to help keep UAH #ChargerSecure
Sincerely,
UAH CISO and Director of Client Services
Office of Information Technology