Most organisations implement MFA and consider themselves protected. They are not. MFA prompt bombing, the technique used by APT-29, Lapsus$, and criminal ransomware groups, bypasses application-based MFA by flooding users with approval requests until they accept. We test your organisation's resilience to these attacks.
MFA is not a silver bullet. Our CREST-registered testers probe every layer of your authentication stack, from rate-limiting configuration to device enrollment portals, using the same techniques employed by nation-state actors and ransomware operators.
Used by APT-29 (Cozy Bear) targeting government and defence, Lapsus$ targeting Microsoft, Uber, and Samsung, and multiple ransomware-as-a-service groups targeting NHS and financial services. CE+ certification does not currently test MFA resilience. This is an uncovered gap.
Targeted by these groups
Map all MFA-protected surfaces, authentication providers (Entra, Okta, Duo), and enrollment portals.
Execute controlled prompt bombing campaigns against test accounts, measuring user response rates and system rate-limiting behaviour.
Attempt unauthorised MFA device re-enrollment post-approval to identify portal access gaps.
Detailed findings with specific configuration changes for your authentication provider, policy tuning recommendations, and staff awareness guidance.
CE+ certification does not test MFA resilience. Our CREST-registered assessment gives you proof of what your authentication stack can and cannot withstand, with specific hardening steps for your authentication provider.
Assessment covers: