Summary
In this episode of the Blue Security Podcast, hosts Andy and Adam delve into a significant surge in external ID charges experienced by a customer, leading to the discovery of an international revenue share fraud attack. They discuss the mechanics of this fraud, how it exploits telecommunication systems, and the importance of monitoring and mitigating such attacks. The conversation emphasizes the need for organizations to implement security measures, including web application firewalls and billing alerts, to prevent financial losses from similar attacks. The episode concludes with key takeaways and recommendations for enhancing security in external identity management.
----------------------------------------------------
YouTube Video Link: https://youtu.be/6jXBULGx5aA
----------------------------------------------------
Documentation:
https://learn.microsoft.com/en-us/entra/architecture/deployment-external-operations
https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mfa-telephony-fraud
https://learn.microsoft.com/en-us/entra/external-id/customers/how-to-region-code-opt-in
https://learn.microsoft.com/en-us/entra/external-id/customers/concept-multifactor-authentication-customers#sms-pricing-tiers-by-countryregion
----------------------------------------------------
Contact Us:
Website: https://bluesecuritypod.com
Bluesky: https://bsky.app/profile/bluesecuritypod.com
LinkedIn: https://www.linkedin.com/company/bluesecpod
YouTube: https://www.youtube.com/c/BlueSecurityPodcast
-----------------------------------------------------------
Andy Jaw
Bluesky: https://bsky.app/profile/ajawzero.com
LinkedIn: https://www.linkedin.com/in/andyjaw/
Email:
[email protected]
----------------------------------------------------
Adam Brewer
Twitter: https://twitter.com/ajbrewer
LinkedIn: https://www.linkedin.com/in/adamjbrewer/
Email:
[email protected]