InformationalTLP:CLEARGARNET-CSIRT-2026-003

Recommended: enable multi-factor authentication on GARNET accounts

As phishing activity against the community increases, GARNET CSIRT strongly recommends enabling multi-factor authentication (MFA) on all accounts that support it. This advisory explains why and how.

Informational severity. For awareness.

Why this matters

Most account compromises we handle start with a stolen password — through phishing, reuse across sites, or a data breach elsewhere. Multi-factor authentication (MFA) adds a second check (an app prompt, security key, or one-time code) so a stolen password alone is not enough to sign in.

  1. Turn on MFA for your GARNET email and any service that offers it. Prefer an authenticator app or a hardware security key over SMS codes where possible.
  2. Register a backup method (a second device or recovery codes) so you are not locked out if you lose your phone.
  3. Use a unique password per service — a password manager makes this practical.

Need help?

If you are unsure how to enable MFA on a specific service, or you manage a system for the community and want to require MFA, contact the team. This advisory is informational — there is no active threat tied to it, but acting on it meaningfully reduces your risk.

§ Verify this advisory✓ PGP-signed

This advisory is published with a detached PGP signature against the CSIRT key. Confirm it is genuine and unmodified before acting:

$ curl -O https://csirt.garnet.edu.gh/advisories/2026-003-community-mfa-rollout.md
$ curl -O https://csirt.garnet.edu.gh/advisories/2026-003-community-mfa-rollout.md.asc
$ gpg --import garnet-csirt.asc
$ gpg --verify 2026-003-community-mfa-rollout.md.asc 2026-003-community-mfa-rollout.md

Downloads: source .md · signature .md.asc · public key. Check the fingerprint (684C7B7DA77E4F1B68AED3ECE84B541C6184CC6F) on the PGP page — if gpg reports a “Good signature” from that key, this advisory is authentic.


Think a system in the community is affected or compromised?Report an incident