Skip to content

Search ThreatNotes

Why MFA Fatigue Attacks Work

The failure is not that users are careless. It is that push approval asks a question the user has no way to answer correctly — and asks it dozens of times until they slip.

  • mfa
  • authentication
  • social-engineering
4 min read

Social Engineering Isn’t Just Email

We spent a decade teaching everyone to be suspicious of their inbox. Attackers responded by picking up the phone — where nobody is watching, nobody was trained, and being helpful is literally in the job description.

  • social-engineering
  • human-factors
9 min read

Anatomy of a Phishing Email

Stop trying to sense whether an email “feels off”. A phishing message has five jobs it must do to work, and every one of them leaves a mark you can check in about eight seconds.

  • phishing
  • social-engineering
  • email-security
8 min read

All posts