Skip to main content
Home
We keep your Housing Authority safe, secure, and productive — so you can focus on serving your community.
  • Home
  • Housing Authorities
    • Small Housing Authority
    • Medium and Large Housing Authority
  • Services
    • Voip Phone Service
  • Articles
  • Testimonials
  • About
  1. Home

When the Security Prompt Is Real, But the Person Asking You to Approve It Isn't

When the Security Prompt Is Real, But the Person Asking You to Approve It Isn't

For years, we've trained people to trust one thing above almost everything else in cybersecurity: the authentication prompt on their phone.  See a legitimate-looking notification from Microsoft, approve it, and move on with your day.  That instinct has protected a lot of organizations from a lot of attacks.

It's also exactly what a newer wave of attackers is now counting on.

Attackers Aren't Breaking In. They're Being Let In.

One of the reasons today's cyberattacks are so hard to catch is that many of them no longer look like "hacking" at all.  There's no obvious break-in, no malware alert, and no suspicious link.

Instead, attackers are learning how to work with your normal business processes and with your employees to get what they want.

Microsoft recently issued a warning about a group it tracks as Storm-2949, which has been targeting the password reset process built into Microsoft accounts.

How the Attack Works

The attack doesn't start with a hack.  It starts with information the criminals already have, usually something as simple as an employee's email address and phone number, often gathered from a previous data leak or basic reconnaissance.

From there, the sequence looks like this:

  1. The attacker triggers a password reset on the victim's Microsoft account.
  2. At the same time, they call the employee, posing as IT support.
  3. The employee receives a real Microsoft authentication prompt because a real password reset request was initiated.
  4. The caller, sounding calm and professional, explains that approving the prompt will "fix" the issue the employee is supposedly experiencing.
  5. The employee approves the request, giving the attacker what they need to take over the account.

What makes the attack so effective is that nothing about it feels fake. The notification is genuine.  The system generating it is genuine.  The only thing that isn't genuine is the person on the phone.  By the time the employee realizes, the damage is often already done.

Once attackers gain control, they can reset the password, lock the legitimate user out, and begin moving through whatever that account has access to.  In several reported cases, attackers extracted large volumes of data from OneDrive.  Because employees often have access to shared files and departmental resources, a single compromised account can expose far more than just one person's data.

Why This Matters More Than a Typical Phishing Email

Multi-Factor Authentication (MFA), the extra step that requires approval through a phone, authenticator app, or security code, remains one of the strongest security controls available.  That hasn't changed.

What has changed is that attackers have become adept at convincing people to bypass MFA voluntarily simply by sounding credible and asking them to do it.

This is a reminder that cybersecurity is no longer purely a technical problem.  Increasingly, it's a human one.

People are naturally inclined to cooperate with someone who sounds professional, calm, and helpful, especially when a real security prompt appears on their screen at exactly the same moment.  That combination is what makes this style of social engineering so effective, and so different from the poorly written phishing emails that many employees have learned to spot.

What Organizations, Especially Housing Authorities and Public Agencies, Should Do

For the housing authorities and public agencies we work with, this type of attack is particularly concerning.

These organizations manage sensitive resident information, HUD/PIH-related data, and shared files spanning multiple departments.  In environments like these, a single compromised account can quickly become a much larger data exposure event.

Every organization should have the following controls in place:

Establish a Clear Password Reset Process

Create a documented, repeatable process for password resets and account changes that does not rely solely on a phone call.

Never Approve Unsolicited Authentication Requests

Make it a standing policy that IT support will never ask employees to approve an authentication prompt they did not personally initiate.

Train Staff on This Specific Scenario

Security awareness training should cover more than suspicious links and email attachments.  Employees should understand that they must never approve authentication prompts triggered by someone else, even when the request appears legitimate.

Provide a Verification Method

Give employees a simple, trusted way to verify support requests before acting, such as disconnecting the call and contacting IT through a published support number.

The Real Question to Ask Your Team

Consider this scenario:

You're on the phone with someone who sounds exactly like IT support.  At that same moment, a real Microsoft authentication prompt appears on your phone.

Would you feel confident deciding whether the request was legitimate?

If your honest answer is "I'm not entirely sure," that's not a personal failing.  It's a sign that your organization needs clearer processes, not just more awareness.

Security tools like MFA are only as strong as the judgment of the people using them, and that judgment should be supported by policy and procedure, not left to instinct alone.

 

About Ultimate IT Guys

Ultimate IT Guys helps housing authorities and public agencies build the security processes, training, and monitoring needed to stay ahead of attacks like this one.  If you're not sure your organization has a clear policy for handling unexpected authentication requests, that's a good place to start the conversation.

Security

  • Copyright Ultimate IT Guys LLC 2008 to 2026
  • Affiliate Disclaimer
  • Privacy Policy
  • Website Terms of Use