A fake city-benefits enrollment site captures logins after staff approve a flood of MFA prompts. What access method is this?
Select an answer to reveal the explanation.
Short Explanation
Staff got tired of tapping Allow and walked their real login into a fake benefits page. That is credential phishing plus MFA fatigue—social pressure on the prompt, not a kernel bug. The phone buzzed them into handing over the session.
Full Explanation
A look-alike civic enrollment site that succeeds after users approve repeated MFA challenges is credential phishing combined with MFA-fatigue abuse. A kernel exploit, SQL injection, and wormable vendor malware would not depend on users accepting push prompts at a fake site. The access method is social-plus-identity, not a local exploit.