Your phone, a work evening, and a series of small decisions - each one a door.
10 minutes. The Uber MFA-fatigue breach played as decisions, a red-flag drill, and 8 judgment calls. A safety score with feedback on every decision.
Before you start
Free for everyone. All drills are free - finish and you get a verifiable certificate.
Uber said an attacker compromised an external contractor's account. Uber believed the contractor's corporate password was likely purchased on the dark web after malware infected the contractor's personal device. The attacker repeatedly attempted to log in, generating two-factor authentication requests; the contractor initially rejected them but eventually accepted one. Uber said it believed the attacker was affiliated with Lapsus$. The attacker subsequently accessed several employee accounts and tools, including G-Suite and Slack.
Separately: the attacker told TechCrunch that after sending push notifications for more than an hour, they contacted the contractor on WhatsApp pretending to be Uber IT and said accepting a request would stop the notifications. (The attacker's account, as reported by TechCrunch - not Uber-confirmed.)
No reliable public dollar-loss figure was disclosed. None is stated here.
The muscle memory: the attacker already had the password. The prompts were the last door - and a human hand opened it.
You are Jordan, on the ops team at a financial services firm. You are not at work. You are not logging in to anything.
YOUR PHONE
The evening is quiet. Then it isn't.
If not, stop. Don't approve the request or use the link until you've independently verified it through your firm’s known channel. Then report anything suspicious.
An authentication factor - a push, a code, a QR enrollment - belongs in a flow you expected or initiated. Legitimate re-enrollment, recovery, and step-up prompts exist; anything unexpected verifies through your firm’s known channel first. That catches many MFA-fatigue, phishing, vishing, and fraudulent-enrollment attacks even when the lure changes.
Around the same time as the Twilio attack, Cloudflare saw an SMS-phishing attack with very similar characteristics. At Twilio, employees entered credentials on the phishing pages; the attacker ultimately accessed data belonging to approximately 209 customers (Twilio's updated count, October 2022 - up from an initial 125 reported in August). At Cloudflare, at least 76 employees received the phishing texts and three entered credentials - but Cloudflare requires physical FIDO2/WebAuthn security keys, the attackers could not get past that requirement, and no systems were compromised.
Humans at both companies could be fooled by near-identical lures. The authentication architecture mattered: even with three sets of credentials stolen, security keys kept them from being enough. Employee judgment can stop the lure. Phishing-resistant MFA can keep stolen credentials from becoming a breach.
Tap every item that is a warning sign. Leave legitimate controls untapped. Then check your work.
This certifies that
has completed Module 18 - The Push Storm: never authenticate what you didn't start on with a safety score of /100 in of active time.
Safety score - credential defense: how your decisions held up, graded 0-100.
Objective: Unexpected authentication requests are stopped and verified independently through the firm's known channel before any approval; suspicious contacts are reported.
Seat time ~10-15 minutes. Verify this certificate at aisafety101.com/verify.
Evidence on record: module completion, seat time, final score, and certificate ID. This certificate ID verifies in your firm's admin report.
Your one rule to keep: "Did I expect or initiate this authentication?" If not, stop - don't approve through the unexpected request; verify independently through your firm’s known channel and report anything suspicious.