Arctic Wolf has recently observed customers receiving unsolicited Microsoft multi-factor authentication (MFA) text messages. These messages originate from legitimate Microsoft short code numbers; however, the source and intent have not been confirmed. This issue appears widespread, affecting organizations across multiple industry verticals.
Example of Text Message
It is currently unclear whether this activity is due to a systemic issue on Microsoft’s side or part of a malicious campaign. At this time, Arctic Wolf has not identified any malicious activity or unauthorized access associated with these unexpected MFA prompts.
Recommendation
Avoid Interacting With Unsolicited MFA Authentication Messages
Avoid interacting with any unsolicited MFA requests and report them to your security team.
Resources