MFA Fatigue Attack
An MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
An MFA fatigue attack — also called MFA bombing or push notification spamming — exploits the "approve/deny" prompt of push-based multi-factor authentication. The attacker already has the victim's username and password (obtained through phishing, credential stuffing, or data breaches) and repeatedly triggers MFA prompts until the user approves one, either by accident, frustration, or confusion.
How it works
- Credential acquisition. The attacker obtains a valid username and password — often from a breached credential database, an infostealer log, or a phishing page.
- Repeated login attempts. The attacker initiates login after login, each triggering a push notification on the victim's phone. Notifications may arrive dozens of times in minutes, often late at night or early in the morning.
- Social engineering assist. In more sophisticated variants, the attacker calls or texts the target — posing as IT support — and tells them to approve the next prompt to "fix an account issue" or "stop the notifications." This combination of vishing and MFA fatigue was used in the 2022 Uber breach.
- Access. Once the victim taps "approve," the attacker has authenticated and gains access to the account.
MFA fatigue works because push-based MFA shifts the decision to a single tap with minimal context. The user sees a prompt but often cannot tell whether it was triggered by their own action or by an attacker.
How to defend against it
- Switch to phishing-resistant MFA — FIDO2/WebAuthn hardware keys or passkeys eliminate push notifications entirely and cannot be approved accidentally.
- Enable number matching on push-based MFA providers. This requires the user to enter a code displayed on the login screen, preventing blind approval.
- Rate-limit authentication attempts and alert the SOC when an account receives repeated MFA prompts in a short window.
- Simulate MFA fatigue scenarios to train employees to recognize unusual prompt patterns and report them rather than approving. The NOUSEC platform can test employee responses to unexpected authentication requests.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo