One accidental approve on a mobile push prompt can finish a workforce login after the password is already stolen. No malware on the laptop is required at that step. According to CISA on 31 October 2022, organizations should implement phishing-resistant MFA against phishing and other known cyber threats, and shops still on mobile push should enable number matching to blunt MFA fatigue. The same year saw widely reported enterprise push-bombing and SMS or app-OTP phishing patterns. Public reporting on the alert page itself does not name individual victim companies, record counts, or a threat actor.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

What did CISA actually publish on 31 October 2022?

CISA published an alert plus two fact sheets on implementing phishing-resistant multifactor authentication and implementing number matching in MFA applications, and pointed readers to the MFA options hierarchy on CISA.gov/MFA. According to the CISA alert, the agency “strongly urges all organizations to implement phishing-resistant MFA to protect against phishing and other known cyber threats.” For shops still on mobile push, the same alert recommends number matching when phishing-resistant MFA is not yet possible. This is federal control guidance, not a victim 8-K or ransomware filing.

How does MFA fatigue defeat ordinary push MFA?

MFA fatigue defeats ordinary push MFA when an attacker already has the password and spams approve prompts until a user taps once without reading. That single accidental approve completes login. No OTP seed theft or malware on the laptop is required at that stage. CISA’s number-matching recommendation exists specifically because blind one-tap accept turns a stolen password into a live workforce session. Public reporting on the CISA alert does not attribute a named actor or list named corporate victims for that failure mode.

Is number matching as strong as phishing-resistant MFA?

No. Number matching is not as strong as phishing-resistant MFA. CISA states that directly: although number matching is not as strong as phishing-resistant MFA, it is one of the best interim mitigations for organizations that cannot move immediately. Number matching only stops blind push approval. It does not origin-bind the ceremony the way FIDO or WebAuthn-class phishing-resistant authenticators do, and it does not fix OTP codes a user can still type into the wrong page. Phishing-resistant factors harden the login ceremony; phishing-proof MFA 2.0 is the stronger full-lifecycle bar the companion covers.

Does this guidance also target phishable OTP and fake logins?

Yes. CISA’s push for phishing-resistant MFA is aimed at phishing and other known threats that still beat SMS codes, app OTP, and similar transferable second factors. Those factors can be entered on a fake or proxied login and completed in real time while the real IdP issues a session. Number matching does not solve that path. Phishing-resistant MFA is the control CISA ranks above interim push hardening. Public reporting on the alert page does not name a specific adversary-in-the-middle kit, TAP enrollment abuse, or device-code flow.

Why is November 2022 archived as CISA guidance instead of a named breach?

November 2022 is archived here as CISA guidance because this slot is a technique month, not a single named-org data breach with household records or a ransom figure. Public reporting does not establish affected-record counts, ransom amounts, or threat-actor attribution for this item. The alert still matters: it codifies what broke across 2022 workforce MFA (push fatigue and phishable OTP) and what federal guidance expected next. A phishing-proof fix stronger than legacy push or OTP exists; the companion covers prevention without replaying this FAQ.