Skip to case study
All case studies

Case study Enterprise

MFA-Fatigue Targeting Surfaced Early

Unit6 detected chatter selecting multiple employees for a likely phishing and MFA-fatigue campaign. The activity was still preparatory, assessed at a low threat level, with no confirmed account takeover.

ThreatAn actor was preparing a campaign against multiple employee identities
What Unit6 sawIdentities selected for MFA fatigue
What was at riskEmployee targeting detected early

Impact summary

Unit6 detected chatter selecting multiple employees for a likely phishing and MFA-fatigue campaign. The activity was still preparatory, assessed at a low threat level, with no confirmed account takeover.

Illustrative close-up of a phone with an unreadable notification glow

01 / Observation

What Unit6 saw

Unit6 observed:

  1. 01

    Chatter about a set of employee identities

  2. 02

    A likely combination of phishing and MFA push fatigue

  3. 03

    A low current threat assessment despite the actor’s prior track record

02 / Significance

Why it mattered

An MFA-fatigue attack depends on people accepting an unexpected authentication request. The preparation can begin before a login system sees the decisive event.

Potential targets were identified. A sent phish or approved MFA prompt was not confirmed.

03 / Confidence

How Unit6 established confidence

Targeting chatter indicating phishing and MFA-fatigue techniques

The identities and exact number of targets are deliberately withheld here.

04 / Recommended response

What the customer could do

Before any takeover was confirmed, the evidence supported:

  • Warn and protect the targeted identity group without disclosing the target list publicly
  • Review MFA enrollment and use phishing-resistant authentication where feasible
  • Watch for suspicious sign-in attempts and repeated authentication prompts

05 / Outcome not confirmed

Outcome

If the planned campaign progressed, a targeted user might approve a fraudulent prompt or disclose credentials.

An attempted phish, successful login, and customer response remain unconfirmed.

See what happens when you know first.

You’ve seen their hands.
Now let’s look at yours.

Book a demo