Skip to Main Content
October 18, 2022

Beware of “Prompt bombing” – multiple pings trying to trick you

Cybersecurity Awareness Month / #31Days of Cybersecurity

A new form of social engineering known as “prompt bombing” uses multiple pop-up prompts to catch distracted users off guard and cause them to bypass multi-factor authentication. Often the prompts are from imposters posing as your IT staff, other staff or your provider security staff.  This scam “bombs” the user with repeated pop-up notifications that require you to pick an option or enter your log in credentials in order to close out. The prompts will continue to come in, often after work hours, to try to annoy you enough to pick an option just to make it stop.

 The criminal can then take over your email and send out hundreds of malicious emails using your official email address. Repeated, unexpected pop-ups that ask for credentials are a red flag of potential prompt bombing.  

  ACTION STEPS:   

  See our CTR Cyber page for cybersecurity internal controls. Departments should contact [email protected] with any incidents or suspected incidents of fraud or cyber threats or if you need support from our Statewide Risk Management Team.