<?xml version="1.0"?>
<News hasArchived="false" page="1" pageCount="1" pageSize="10" timestamp="Mon, 20 Apr 2026 00:36:56 -0400" url="https://dev.my.umbc.edu/groups/doit/posts.xml?tag=mfa">
  <NewsItem contentIssues="false" id="152867" important="false" status="posted" url="https://dev.my.umbc.edu/groups/doit/posts/152867">
    <Title>Stop! A DUO Push You Didn't Initiate</Title>
    <Tagline>Cybersecurity Awareness Month</Tagline>
    <Body>
      <![CDATA[
          <div class="html-content"><p>Hello UMBC Community,</p><br><p>We rely on <strong>Duo two-factor authentication</strong> to protect our accounts, and it's an excellent defense. However, cybercriminals are always looking for new ways to get past our security. This week's topic is all about what to do if you receive a Duo push notification you didn't initiate.</p><p>You're working on your computer, not logging into anything new, and suddenly your phone buzzes with Duo push notifications, including SMS texts or phone calls from Duo. What's happening? This is likely an attacker who has obtained your password and is attempting to bypass Duo to access your account.</p><p><strong>Your immediate action is critical.</strong></p><ul><li><p><strong>Do NOT Approve It:</strong> The most important thing is to <strong>never</strong> approve a Duo push notification you did not initiate. Approving it will give the attacker access to your account.</p></li><li><p><strong>Deny the Request:</strong> Decline the request on your phone.</p></li><li><p><strong>Report as Fraudulent:</strong> If you can, mark the notification as fraudulent.</p></li><li><p><strong>Change Your Password:</strong> Immediately change your password on a trusted device or computer. This will invalidate the password the attacker is using.</p></li></ul><p>Remember, a Duo push notification is like a digital handshake. You must be the one to initiate it. If someone else is trying to shake your hand, don't approve the connection!</p><p>If you received a Duo push notification you did not initiate, deny the request, change your password, and immediately report the event to the security team at <strong><a href="mailto:security@umbc.edu">security@umbc.edu</a></strong>. Your report helps protect everyone!</p><p><strong>Stay safe out there.</strong></p><img src="https://my3.my.umbc.edu/groups/doit/posts/152867/attachments/58958" alt="Fraudulent DUO Push Notification with an example." style="max-width: 100%; height: auto;"></div>
      ]]>
    </Body>
    <Summary>Hello UMBC Community,   We rely on Duo two-factor authentication to protect our accounts, and it's an excellent defense. However, cybercriminals are always looking for new ways to get past our...</Summary>
    <AttachmentKind>Image</AttachmentKind>
    <AttachmentUrl>https://assets2-dev.my.umbc.edu/system/shared/attachments/3e667df2a67ad128d5210c451e434bbe/69e5ad69/news/000/152/867/74cf190d5c38c1a052d96e4ad0ec10fd/Week 4.png?1758732647</AttachmentUrl>
    <Attachments>
      <Attachment kind="Image" url="https://dev.my.umbc.edu/groups/doit/posts/152867/attachments/58958"></Attachment>
      <Attachment kind="Flyer" url="https://dev.my.umbc.edu/groups/doit/posts/152867/attachments/58996"></Attachment>
    </Attachments>
    <TrackingUrl>https://dev.my.umbc.edu/api/v0/pixel/news/152867/guest@my.umbc.edu/2cc7078ed3918c2bb439a52bc0d0239e/api/pixel</TrackingUrl>
    <Tag>cybersecurity</Tag>
    <Tag>mfa</Tag>
    <Tag>security</Tag>
    <Group token="doit">Division of Information Technology (DoIT)</Group>
    <GroupUrl>https://dev.my.umbc.edu/groups/doit</GroupUrl>
    <AvatarUrl>https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
    <AvatarUrl size="original">https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/original.JPG?1727453227</AvatarUrl>
    <AvatarUrl size="xxlarge">https://assets1-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxlarge.png?1727453227</AvatarUrl>
    <AvatarUrl size="xlarge">https://assets3-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xlarge.png?1727453227</AvatarUrl>
    <AvatarUrl size="large">https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/large.png?1727453227</AvatarUrl>
    <AvatarUrl size="medium">https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/medium.png?1727453227</AvatarUrl>
    <AvatarUrl size="small">https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/small.png?1727453227</AvatarUrl>
    <AvatarUrl size="xsmall">https://assets2-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xsmall.png?1727453227</AvatarUrl>
    <AvatarUrl size="xxsmall">https://assets4-dev.my.umbc.edu/system/shared/avatars/groups/000/000/021/d27760c5de12c74b73faec8d0e631acf/xxsmall.png?1727453227</AvatarUrl>
    <Sponsor>Division of Information Technology (DoIT)</Sponsor>
    <ThumbnailUrl size="xxlarge">https://assets3-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/xxlarge.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="xlarge">https://assets3-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/xlarge.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="large">https://assets3-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/large.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="medium">https://assets2-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/medium.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="small">https://assets2-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/small.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="xsmall">https://assets3-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/xsmall.jpg?1758732569</ThumbnailUrl>
    <ThumbnailUrl size="xxsmall">https://assets4-dev.my.umbc.edu/system/shared/thumbnails/news/000/152/867/b70cbf9796f10cb59eabad854ce1ca91/xxsmall.jpg?1758732569</ThumbnailUrl>
    <ThumbnailAltText>Cybersecurity Awareness Month: Fraudulent DUO Push Notifications</ThumbnailAltText>
    <PawCount>16</PawCount>
    <CommentCount>0</CommentCount>
    <CommentsAllowed>true</CommentsAllowed>
    <PostedAt>Mon, 13 Oct 2025 09:01:44 -0400</PostedAt>
  </NewsItem>
</News>
