GlossarySecurity awareness

MFA fatigue

Short answer

MFA fatigue, or push bombing, is an attack in which someone who already has a user's password sends repeated MFA push notifications until the user approves one, out of confusion, annoyance or after a fake call from IT support. One approval is enough to give the attacker access.

How it works

The attacker obtains the password through phishing, an infostealer or credential stuffing, then tries to sign in again and again, generating a stream of approval requests on the victim's phone, often at night. Many attackers combine this with a message or call pretending to be IT support and asking the user to accept the prompt.

A known case

In the 2022 breach at Uber, an attacker with a contractor's password sent repeated MFA requests and then contacted the contractor on WhatsApp, posing as IT support. The contractor accepted a request, which gave the attacker access to internal systems.

Prevention

Use number matching, where the user must type a number shown on the login screen, and show the location and application in the prompt. Limit the number of push requests and alert on bursts of them. For administrators and high risk roles, move to phishing resistant methods such as passkeys or security keys. Conditional access can block sign ins from unknown devices before a prompt is even sent.

What users should know

Never approve a request you did not start, and report unexpected prompts immediately, because they mean someone already has your password. IT will never ask you to accept an MFA prompt by phone or chat. These messages belong in security awareness training, and an unexpected prompt should trigger a password reset.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub