MFA Fatigue
An attack that bombards a victim with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
Definition
MFA fatigue, also called push bombing, is an attack technique in which an adversary who already has a victim's username and password repeatedly triggers multi-factor authentication push notifications, hoping the victim will eventually approve one to make the notifications stop or by mistake. It exploits the human tendency toward habit and frustration rather than a technical flaw in the authentication method itself.
The attack begins after credentials have already been stolen, typically through a prior phishing attack or a data breach, so the attacker has valid login details but is blocked by a second authentication factor. The attacker repeatedly attempts to log in, generating a stream of push notifications on the victim's phone, sometimes at inconvenient times such as late at night. Facing a barrage of alerts, some victims tap approve simply to silence the notifications, misinterpret it as a system glitch, or believe it might be a legitimate request from IT.
MFA fatigue matters because it defeats one of the most widely deployed defenses against account takeover, multi-factor authentication, by targeting the human approval step rather than the cryptography behind it. High profile breaches at major technology and ride-sharing companies have been attributed to this technique, showing that even well resourced organizations are not immune. Any organization using push-based MFA without additional context is exposed to this risk, regardless of sector or size.
The most effective mitigation is moving from simple approve or deny push notifications to number matching, where the user must enter a code shown on the login screen into the app, which prevents accidental approval. Rate limiting authentication attempts and alerting security teams to unusual volumes of MFA requests for a single account helps catch an attack in progress. Employees should be trained to treat unexpected MFA prompts as a signal to change their password and report the activity immediately, never to approve a request they did not initiate.
At a glance
- Severity
- High
- Prevalence
- Common in credential-based attacks
- Primary targets
- Users with push-based MFA already enrolled, especially after credential theft
- Also known as
- Push bombing
How it works
- 1
Prior credential theft: the attacker already has a valid username and password, usually from phishing or a data breach.
- 2
Repeated prompts: they repeatedly attempt to log in, triggering a stream of push notifications on the victim's phone.
- 3
Timing pressure: attempts often happen at inconvenient times, such as late at night, to increase confusion and fatigue.
- 4
Accidental or frustrated approval: facing a barrage of alerts, the victim taps approve to silence the notifications or believes it is a system glitch.
- 5
Account access: the attacker uses the approved session to sign in as the legitimate user, defeating the second authentication factor.
Warning signs
- Multiple MFA push notifications you did not request, especially in a short period
- Prompts arriving late at night or outside normal working hours
- A notification you almost approved out of habit or frustration
- Login alerts for locations or devices you do not recognize
- Colleagues receiving similar unexpected authentication prompts
How to defend
- Never approve an MFA prompt you did not personally trigger
- Move from simple approve or deny push notifications to number matching
- Report repeated unexpected prompts to security immediately and change your password
- Enable rate limiting on authentication attempts where available
- Monitor for unusual volumes of MFA requests tied to a single account
Real-world example
An IT administrator at an Indonesian telecom provider receives a dozen MFA push notifications within a few minutes, late at night, all for a login they did not initiate. Exhausted and assuming it is a glitch, they tap approve on one, unknowingly granting the attacker, who already had their stolen password, access to the corporate network.
How Claro helps
Claro's awareness modules include MFA fatigue scenarios so employees learn to deny and report unexpected authentication prompts instead of approving them out of habit.
Frequently asked questions
Why is MFA fatigue effective against multi-factor authentication?
It does not attack the cryptography behind MFA at all. Instead, it targets the human approval step, wearing the victim down with repeated push notifications until they approve one out of frustration, confusion, or habit.
How is MFA fatigue different from a normal MFA prompt?
A normal prompt appears once, right after you attempt to log in yourself. MFA fatigue involves repeated, unsolicited prompts you did not trigger, sometimes arriving in a rapid burst or at unusual hours, which is the key warning sign.
Does number matching stop MFA fatigue attacks?
Yes, largely. Number matching requires the user to read a code from the login screen and type it into the app, rather than simply tapping approve, which prevents accidental or fatigued approval of a request the user never initiated.
What should I do if I receive unexpected MFA prompts?
Deny every prompt you did not trigger, change your password immediately, and report the activity to your security team. Treat repeated unexpected prompts as a sign your credentials have already been compromised.
Related terms
Multi-Factor Authentication (MFA)
A security method that requires two or more independent proofs of identity before granting access to an account or system.
Account Takeover
When an attacker gains unauthorized control of a user's online account, typically through stolen credentials, and uses it for fraud or further attacks.
Social Engineering
The manipulation of people into revealing sensitive information or taking unsafe actions by exploiting trust, emotion, and human psychology rather than technical flaws.
Credential Harvesting
Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.
Reduce your human risk
Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.
Request a demo