The Phone Call That Beat the MFA
Most people think of multi-factor authentication as the thing that makes a stolen password useless. Mostly it does. What the Cisco breach showed, better than any training slide, is that the second factor is only as strong as the moment a person decides whether to approve it, and that moment can be manipulated with an ordinary phone call.
According to the account Cisco's Talos team published in August 2022, the targeted employee received calls from several different people over a period of time, speaking English in a range of accents, each presenting as someone from a support organisation the employee would plausibly trust. At the same time, push prompts kept arriving on the employee's phone. The calls gave the prompts a story. Eventually one was accepted, and the attacker was on Cisco's VPN as that employee.
The attacker did not need to break the MFA. They needed the person holding it to believe, for about two seconds, that approving it was the helpful thing to do. That is a phone skill, not a hacking skill, and it is why we treat voice security and account security as the same problem.
If this sounds familiar it is because the approach has only grown since. The extortion groups behind the long run of Salesforce, Okta and help desk related breaches through 2025 and 2026 leaned heavily on voice calls to staff, impersonating IT, and the recent RingCentral data theft was also attributed to a social engineering campaign. We cover the voice side in depth in our guide to voice cloning and vishing, which is worth reading alongside this one.
Both Incidents on One Page
| Date | Event |
|---|---|
| Before May 2022 | A Cisco employee's personal Google account is compromised. It holds their Cisco credentials because Chrome was syncing saved passwords to it. |
| May 2022 | Voice phishing calls and repeated MFA push prompts. One is approved. The attacker gets VPN access, enrols new MFA devices and moves inside the network. |
| 24 May 2022 | Cisco detects the intrusion and begins removing the attacker. |
| 10 Aug 2022 | Cisco discloses. The Yanluowang ransomware group posts a file list. Cisco attributes the intrusion to an initial access broker with links to UNC2447, Lapsus$ and Yanluowang, says no ransomware was deployed, and says the Box folder data taken was not sensitive. About 2.8GB of files is later published. |
| Early May 2024 | ZEIT Online and the Netzbegrünung researchers report that Webex meeting links for German federal bodies can be found by counting up or down from a known link. |
| May 2024 | More than 6,000 past and future meetings reported as discoverable, with titles, times and invitees visible. The Bundeswehr disconnects its Webex system from the internet as a precaution. |
| 28 May 2024 | Cisco has the Webex Meetings bugs patched worldwide. |
| 15 Oct 2024 | Cisco responds to a separate data leak claim, attributing it to a public facing DevHub resource. Covered briefly below. |
Before going further, a fairness note. Cisco detected the 2022 intrusion itself, published one of the most candid breach write-ups a large vendor has ever released, and fixed the 2024 flaws within weeks of them being reported. Plenty of companies with the same problems never tell anyone. The reason to study Cisco is that the lessons are well documented, not that Cisco was unusually weak.
Way In Number One: A Person
Strip the Cisco breach down and there are three human decisions in it, none of which would seem unusual in an Australian office.
Decision one: saving a work password in the browser, signed in with a personal account. This is how most people use Chrome at home, and plenty carry the same habit onto a work laptop. The effect is that a business credential quietly lives inside a personal account the business cannot see, secure or switch off. Whatever happens to that personal account happens to the work password as well.
Decision two: taking a support call at face value. The callers claimed to be from organisations the employee would expect to hear from. Nothing in most workplaces tells staff how to check that. The polite response to somebody saying they are fixing your account is to help them.
Decision three: approving a prompt. After enough calls and enough buzzing, one tap on "approve" feels like the way to make it stop. It is also the only thing the attacker actually needed.
Each decision is reasonable on its own. Put together, they are a complete route into a network. The good news is that a business can change the default at every one of them without asking anybody to become a security expert.
Take passwords out of personal profiles
Give staff a business password manager the business controls. On managed devices, stop work profiles syncing to personal accounts. Now a compromised personal account holds nothing of yours.
Make "we never ring for codes" a known rule
One sentence, said often: nobody from this business or our providers will ever ring you and ask you to approve a sign-in or read out a code. The call stops being confusing and becomes obviously wrong.
Replace the approve button
Use number matching or passkeys so that a prompt cannot be approved without information from the genuine login screen. The attacker's two seconds of persuasion are no longer enough.
Why Approve or Deny Is the Weak Link
The technical name for flooding somebody with prompts is MFA fatigue, or push bombing. It works for a simple reason. An approve or deny notification asks a person to make a security decision with no information, at a time the attacker chose, with a single tap as the easy way out. There is no way to tell a genuine prompt from a malicious one by looking at it.
Here is how the common options stack up for a small business, ordered from weakest to strongest.
| Option | What the user does | Would it have stopped the Cisco route? |
|---|---|---|
| Approve or deny push | Taps a button | No. This is the method that was beaten. |
| SMS or emailed code | Types a code sent to them | Not reliably. A caller can simply ask for the code, and SMS is exposed to SIM swap. |
| Authenticator app code | Types a rotating code | Not reliably. Same problem: it can be read out to somebody on the phone. |
| Push with number matching | Types the number shown on the real login screen | Very likely. A blind approval is impossible, and a user asked to read a number to a caller has a clear signal something is off. Microsoft made this the default in its Authenticator app in 2023. |
| Passkey or hardware security key | Uses a fingerprint, face or a key tied to the genuine site | Yes. There is nothing a caller can persuade anybody to hand over, and it will not work on a fake site. |
A sensible target for most small businesses is number matching for everybody and passkeys or hardware keys for the handful of accounts that could do the most damage: administrators, whoever can move money, and whoever can change your phone system. That last one is often forgotten. Somebody with admin access to a phone system can redirect your main number, change voicemail, or forward calls overseas at your expense. We covered that category of fraud in what AI security catches on the phone line.
Check the prompt limit while you are there
Whatever method you choose, find the setting that stops prompts after a few denials and alerts an administrator. A platform that will quietly send forty prompts at 11pm is doing the attacker's work for them. So is one that lets a new MFA device be added without telling anyone, which is exactly what the Cisco attacker did once inside.
Way In Number Two: A Link
The Webex exposure in 2024 needed no persuasion at all. ZEIT Online, working with researchers from Netzbegrünung, found that the links to Webex meetings used by German federal bodies followed a pattern. Change the number, and you landed on somebody else's meeting details. That applied to scheduled meetings and to fixed personal rooms. More than 6,000 past and future meetings were reported as discoverable, belonging to organisations including the Bundestag, federal ministries, the Chancellery, the information security agency BSI and the Bundeswehr. One reported meeting title concerned the Taurus missile system. The personal meeting room of the head of the German Air Force turned up as well.
Security commentators generally described it as an insecure direct object reference: the system returned information to anybody who asked for the right identifier without checking whether they were entitled to it. Cisco identified the bugs in Webex Meetings and had them fixed worldwide by 28 May 2024. The Bundeswehr disconnected its Webex system from the internet as a precaution and suspended external use while it assessed things.
What makes this incident different from 2022 is that no member of staff did anything wrong. Nobody clicked, nobody approved, nobody took a strange call. The weakness was in how the product was built, and the customers' only protection was the way their own meetings were configured and the vendor's speed in fixing it.
The same pattern hides in plenty of places
Meeting links are the obvious example. Call recording links, voicemail to email attachments, shared transcripts, customer portal links and fax to email can all have the same weakness if identifiers are predictable and lookups are not checked. You cannot inspect your provider's code, but you can ask how these links are generated and protected, and whether they expire.
Why Meeting Details Are Worth Stealing
No recordings leaked in the Webex case. What leaked was metadata: who was meeting, when, and about what. It is easy to underrate that, so here is what the equivalent looks like for an ordinary Australian business.
| Meeting detail | What it tells an outsider |
|---|---|
| "Finance and bank, weekly, Thursday 10am" | When a fake message from "the bank" or a supplier asking for a payment change will look routine. |
| "Client X renewal, pricing" | Which clients a competitor should approach this month, and roughly when. |
| "Restructure, confidential" with HR invited | Something staff and journalists would very much like to know about. |
| An invitee list with external email addresses | Your suppliers, advisers and partners, all ready made targets for impersonation. |
| A fixed personal room link | A standing door that stays the same for years and is often shared widely. |
This is why the meeting standard later in this article includes generic titles and private calendars. They cost nothing and they make a leaked link far less useful, whatever the platform does.
A Footnote on Public Files
A third Cisco incident made headlines in October 2024 and deserves a short mention so the record is complete. After a data broker claimed to have taken a large amount of Cisco data, Cisco's statement of 15 October 2024 attributed the exposure to a public facing DevHub resource used to share code and scripts with customers. It said a small number of files not authorised for public download may have been published, said it had seen no evidence of personal or financial data being involved, and took public access to the portal offline while it investigated. A further release in December was later linked by Cisco to the same incident.
For a small business the lesson is humbler: anything you deliberately made public, a shared folder, a document link, a test site, needs an occasional look to check it only holds what you intended.
Does This Apply to a Ten Person Business?
It is tempting to read about Cisco and the German government and conclude that none of it is relevant to a physio clinic or a plumbing business. We would argue the opposite. Small businesses are exposed to exactly the same two routes, with fewer defences.
- The person route is cheaper to run against small businesses. There is no security team, no formal help desk process, and usually one or two people with access to everything. One persuasive call can reach the owner directly.
- Small businesses rely on the same platforms. The meeting, phone and email tools are the same products large organisations use, so a product flaw affects them equally, without an IT department watching the vendor's security notices.
- The payoff is still worth it. Access to a small business mailbox or phone system can be used to redirect a supplier payment, divert calls, or reach that business's own customers. The attacker does not need your data to be valuable. They need your identity to be trusted.
The controls that follow were chosen with that in mind. They assume no IT staff, a mix of office and mobile workers, and a limited budget.
A Thirty Minute Audit
Sit down with whoever manages your Microsoft 365 or Google Workspace account and your phone system admin login, and work through this list. Each line is a yes or no.
| Check | Where to look | If the answer is no |
|---|---|---|
| Simple approve or deny push is switched off | Identity or authentication method settings | Enable number matching and disable plain push. |
| Admin, finance and phone system accounts use passkeys or security keys | Per user MFA methods | Start with the three most powerful accounts. |
| Adding a new MFA method alerts somebody | Security alerts or audit log settings | Turn on the alert, or at least review the log weekly. |
| Repeated denied prompts are limited | Authentication policy | Set a low threshold and an alert. |
| Work passwords are not synced to personal browser profiles | Browser policy on managed devices, or ask staff | Roll out a business password manager. |
| Staff have been told "we never ring you for codes" | Your last staff email or meeting | Send it today. |
| Meetings default to passcode and lobby | Meeting platform admin settings | Change the default, not just individual meetings. |
| Calendars are private to outsiders | Calendar sharing settings | Restrict to free or busy only. |
| Public links to recordings and files expire | Sharing settings in each tool | Set expiry, then review existing links. |
| You know who to ring at your phone provider in an incident | Your contract or provider portal | Get a name and number now, not during the incident. |
Most businesses we talk to get four or five of these on the first pass. Getting to eight takes an afternoon. The two that take longest are passkeys and the password manager, and both are worth the time.
Rewriting Your Help Desk Script
Whoever resets passwords in your business is your help desk, even if it is the office manager or an outsourced IT provider. Attackers ring help desks pretending to be staff who have lost their phone and need their MFA reset, and it works because the person answering wants to be helpful. The fix is a short script that does not rely on the caller knowing facts that can be found online.
- Never reset MFA or passwords on an inbound call alone. Take the request, then end the call.
- Call back on the number already on file for that staff member, not a number the caller provides.
- For anything involving admin or finance accounts, get a second approval from the person's manager through a separate channel.
- Notify the account owner by a second channel whenever a reset happens, so a real employee finds out immediately if it was not them.
- Write it down and apply it to everyone, including the managing director. The attacker will always claim to be somebody senior and in a hurry.
If your IT is outsourced, ask your provider to show you their version of this script. If they do not have one, that is useful information. The same applies to your phone provider's support team, which is covered in the questions below.
A Meeting Standard You Can Paste
This is short enough to paste into a staff handbook or an onboarding email. It works on any meeting platform, including ours.
Our meeting standard
1. Create a new meeting for anything sensitive. Do not use your personal room link for client, finance or HR meetings. 2. Every meeting has a passcode and a lobby. The host admits people and locks the meeting once everyone expected has joined. 3. Dial-in participants need a PIN. 4. Use plain titles for sensitive meetings. "Catch up" is fine. Client names and deal details go in the agenda, not the title. 5. Our calendars show free or busy to outsiders, never titles or attendees. 6. Record only when there is a reason, tell participants, and delete recordings when they are no longer needed. 7. Anyone unexpected in a meeting gets removed first and asked questions afterwards.
Hybrid and remote teams lean on meetings more than anyone, so if that describes your business, it is worth pairing this with the broader setup in our guide to phone systems for remote and hybrid teams.
The Australian Rules That Apply
None of these incidents happened in Australia, but if something similar happened to an Australian business, a fairly clear set of rules would come into play.
Essential Eight. The Australian Signals Directorate's baseline strategies include multi-factor authentication, and the maturity model has moved towards phishing-resistant methods for important accounts. It is not law for most private businesses, but insurers, auditors and larger customers increasingly ask where you sit against it, and number matching plus passkeys for privileged accounts is a big step in the right direction.
Notifiable Data Breaches. Businesses covered by the Privacy Act must assess a suspected data breach promptly, within 30 days, and notify the OAIC and affected individuals where serious harm is likely. Exposed call recordings, transcripts or meeting details containing personal information can fall within the scheme. Businesses with turnover of $3 million or less are generally exempt, with exceptions such as health service providers, and that exemption still exists as at writing.
Recording and automated decisions. Recording law governs how calls and meetings are recorded and stored, and from 10 December 2026 privacy policies must disclose certain substantially automated decisions that use personal information. Our note on the automated decisions deadline covers what to change.
Scams obligations on providers. Australian telcos now work under tighter anti-scam obligations. They mostly concern scam calls and texts reaching the public, but they reflect the same reality as the Cisco breach: the phone is now one of the main tools of attack.
Seven Questions for Your Provider
These cover both routes. Put them to your phone and meeting provider in writing and keep the answers on file. A provider that takes security seriously will find them easy.
| # | Question | What you want to hear |
|---|---|---|
| 1 | How do your own staff sign in to systems holding my data? | Phishing-resistant MFA for privileged access, no plain push approvals. |
| 2 | If someone rings your support line pretending to be me, what happens? | Verification against details on file, a callback to my registered contact, and a notification to me for any change. |
| 3 | How are meeting, recording, voicemail and transcript links generated? | Long random identifiers, a permission check on every request, and expiry options. |
| 4 | Would you notice someone trying thousands of links? | Rate limiting and alerting, explained specifically. |
| 5 | Can I see who accessed my account and my recordings? | Yes, with an exportable log. |
| 6 | Who else touches my calls, recordings and transcripts? | A short named list, with hosting locations. Every additional party is another route in. |
| 7 | How would you tell me about an incident, and how quickly? | A named process, a realistic timeframe, and enough detail for my own breach assessment. |
Question six is becoming more important every year. Many AI features in phone and meeting products send audio or transcripts to a separate AI company. That may be perfectly sound, but it adds another organisation whose staff can be phished and whose product can have a flaw. We explain how to see through the layers in who actually runs the AI infrastructure.
Where VOCPhone Stands
Here are our answers, briefly, because a list of questions is only fair if we answer them too. VOCPhone owns and operates its own network in Australia rather than reselling somebody else's, the platform is Australian hosted, and support is provided by our own team here. Staff access to systems that hold customer data is protected with strong multi-factor authentication. We will never ring a customer and ask them to approve a sign-in or read out a code, and support changes to an account are verified against the details we hold, with a callback to the registered contact where it matters.
Our AI features, including AI Phone Agents, transcription and call summaries, run inside our own platform rather than being handed along a chain of outside services, which keeps the list of parties touching your calls short. HD video meetings are generated per meeting with passcode and lobby controls, and account administrators can see call and access history. If your insurer or a large customer wants any of that in writing, ask and we will provide it.
No provider can promise a business will never be targeted, and we would be suspicious of one that did. What the Cisco and Webex incidents show is that the routes in are simple and well known. Close the person route with better MFA, a clear rule and a callback habit. Narrow the product route by configuring meetings sensibly and choosing providers who can answer the seven questions without flinching.
Frequently Asked Questions
How did hackers get into Cisco in 2022?
Through a person rather than a technical flaw. According to the account Cisco Talos published on 10 August 2022, an employee had their Cisco credentials saved in Chrome, which was syncing passwords to their personal Google account. That personal account was compromised, giving the attacker the work password. Multi-factor authentication still stood in the way, so the attacker combined voice phishing calls, from several people with different accents claiming to be from trusted support organisations, with a stream of push approval prompts sent to the employee's phone. The calls gave the prompts a believable story, and eventually one was approved. That gave the attacker VPN access as the employee. They enrolled new MFA devices of their own and moved around inside the network until Cisco, which detected the activity on 24 May 2022, removed them. Cisco linked the attacker to an initial access broker associated with UNC2447, Lapsus$ and the Yanluowang ransomware group, said no ransomware was deployed and said the Box folder data taken was not sensitive. About 2.8GB of files was later published. Three ordinary decisions made the route: a work password in a personal browser profile, trusting a support call, and one tap on approve.
What was the Webex vulnerability in 2024?
In early May 2024 ZEIT Online, working with researchers from Netzbegrünung, reported that Webex meeting links used by German federal bodies followed a predictable pattern, so changing the number in a known link revealed other meetings. That applied to scheduled meetings and fixed personal rooms. More than 6,000 past and future meetings were reported as discoverable, with titles, times and invitee details visible, belonging to organisations including the Bundestag, federal ministries, the Chancellery, the information security agency BSI and the Bundeswehr. One reported meeting title concerned the Taurus missile system, and the personal meeting room of the head of the German Air Force was also found. Security commentators generally described it as an insecure direct object reference, where a system returns information to anyone requesting the right identifier without checking whether they are entitled to it. Cisco identified the bugs in Webex Meetings and had them patched worldwide by 28 May 2024, and the Bundeswehr disconnected its Webex system from the internet as a precaution. No staff member did anything wrong. It was a product design weakness, which is why configuration and vendor choice matter as much as training.
What is push bombing, and why does it work?
Push bombing, also called MFA fatigue, is sending a large number of approve or deny sign-in prompts to somebody's phone until they accept one, out of confusion, irritation, or because a caller has told them it is needed. It was the core of the Cisco breach. It works because a simple push prompt asks a person to make a security decision with no information, at a time the attacker chooses, with a single tap as the easiest way out. There is no way to tell a genuine prompt from a malicious one by looking at it. Codes sent by SMS or shown in an authenticator app are not a complete answer either, because a persuasive caller can simply ask for the code. The methods that actually resist it are number matching, where the user must type a number shown on the genuine login screen so blind approval is impossible, and passkeys or hardware security keys, which only work with the genuine site and give a caller nothing to extract. Pair either with a limit on repeated prompts, an alert whenever a new MFA device is added, and a clear rule for staff that nobody will ever ring them asking for approvals or codes.
Is it safe to keep using Webex or other video meeting platforms?
The specific Webex flaws reported in 2024 were patched worldwide by 28 May 2024, and every major meeting platform has had security issues at some point. The practical question is whether your meetings are configured so that a leaked or guessed link gets an outsider very little. Create a new meeting for anything sensitive rather than using a personal room link. Require a passcode and a lobby on every meeting, with the host admitting people and locking the meeting once everyone expected has joined. Require a PIN for dial-in participants. Use plain titles for sensitive meetings and put client names or deal details in the agenda instead. Set calendars so outsiders see only free or busy time, never titles or attendees. Record only when there is a reason, tell participants, and delete recordings when they are no longer needed. Then ask your provider how meeting and recording links are generated, whether it would notice somebody trying thousands of them, and whether you can see an access log. Any provider, including Cisco and including VOCPhone, should answer those questions clearly and quickly.
How should my help desk handle MFA reset requests?
Assume any inbound request to reset a password or MFA device might be an attacker, because ringing a help desk while pretending to be a staff member who lost their phone is one of the most successful techniques of recent years. Whoever does this job in your business, whether it is the office manager or an outsourced IT provider, should follow a short written script. Never reset MFA or passwords on the strength of an inbound call alone; take the request and end the call. Call the person back on the number already on file, never on a number the caller supplies. For administrator, finance or phone system accounts, get a second approval from the person's manager through a separate channel. Notify the account owner by another channel whenever a reset happens, so a genuine employee finds out immediately if it was not them. Apply the script to everyone, including the most senior people, because attackers almost always claim to be somebody important in a hurry. If your IT provider cannot show you their version of this process, ask them to write one, and ask your phone provider the same question about its own support line.
Does the Cisco hack matter for a small Australian business?
Yes, arguably more than for a large one. Small businesses face exactly the same two routes, the person route and the product route, with fewer defences. The person route is cheaper to run against a small business because there is usually no security team, no formal help desk process and one or two people with access to everything, so a single persuasive call can reach the owner directly. Small businesses also rely on the same phone, meeting and email platforms large organisations use, so a product flaw affects them equally without an IT department watching for vendor security notices. And the payoff is still worthwhile to an attacker: access to a small business mailbox or phone system can be used to redirect supplier payments, divert calls or impersonate the business to its own customers. In Australia, businesses covered by the Privacy Act must assess suspected breaches within 30 days and notify the OAIC and affected people where serious harm is likely, and insurers increasingly measure businesses against the Essential Eight, which includes multi-factor authentication. The controls in this article assume no IT staff and a small budget, and most can be done in an afternoon.
What security questions should I ask my business phone provider?
Seven questions cover both routes. How do your own staff sign in to systems holding my data, and do you use phishing-resistant MFA for privileged access? If somebody rings your support line pretending to be me, what verification happens, will you call back my registered contact, and will I be notified of changes? How are meeting, recording, voicemail and transcript links generated, are they random and permission checked, and can they expire? Would you notice somebody trying thousands of links, and how? Can I see who accessed my account and recordings, and export that log? Who else touches my calls, recordings and transcripts, and where are they hosted? How and how quickly would you tell me about an incident, and would you give me enough detail for my own breach assessment? The sixth question matters more each year because many AI features send audio or transcripts to separate AI companies, adding another organisation that could be phished or have a product flaw. Ask in writing, keep the answers on file for your insurer, and treat a vague or slow response as an answer in itself.