Attack technique

MFA Fatigue

An attack that bombards a victim with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.

Definition

MFA fatigue, also called push bombing, is an attack technique in which an adversary who already has a victim's username and password repeatedly triggers multi-factor authentication push notifications, hoping the victim will eventually approve one to make the notifications stop or by mistake. It exploits the human tendency toward habit and frustration rather than a technical flaw in the authentication method itself.

The attack begins after credentials have already been stolen, typically through a prior phishing attack or a data breach, so the attacker has valid login details but is blocked by a second authentication factor. The attacker repeatedly attempts to log in, generating a stream of push notifications on the victim's phone, sometimes at inconvenient times such as late at night. Facing a barrage of alerts, some victims tap approve simply to silence the notifications, misinterpret it as a system glitch, or believe it might be a legitimate request from IT.

MFA fatigue matters because it defeats one of the most widely deployed defenses against account takeover, multi-factor authentication, by targeting the human approval step rather than the cryptography behind it. High profile breaches at major technology and ride-sharing companies have been attributed to this technique, showing that even well resourced organizations are not immune. Any organization using push-based MFA without additional context is exposed to this risk, regardless of sector or size.

The most effective mitigation is moving from simple approve or deny push notifications to number matching, where the user must enter a code shown on the login screen into the app, which prevents accidental approval. Rate limiting authentication attempts and alerting security teams to unusual volumes of MFA requests for a single account helps catch an attack in progress. Employees should be trained to treat unexpected MFA prompts as a signal to change their password and report the activity immediately, never to approve a request they did not initiate.

At a glance

Severity
High
Prevalence
Common in credential-based attacks
Primary targets
Users with push-based MFA already enrolled, especially after credential theft
Also known as
Push bombing

How it works

  1. 1

    Prior credential theft: the attacker already has a valid username and password, usually from phishing or a data breach.

  2. 2

    Repeated prompts: they repeatedly attempt to log in, triggering a stream of push notifications on the victim's phone.

  3. 3

    Timing pressure: attempts often happen at inconvenient times, such as late at night, to increase confusion and fatigue.

  4. 4

    Accidental or frustrated approval: facing a barrage of alerts, the victim taps approve to silence the notifications or believes it is a system glitch.

  5. 5

    Account access: the attacker uses the approved session to sign in as the legitimate user, defeating the second authentication factor.

Warning signs

  • Multiple MFA push notifications you did not request, especially in a short period
  • Prompts arriving late at night or outside normal working hours
  • A notification you almost approved out of habit or frustration
  • Login alerts for locations or devices you do not recognize
  • Colleagues receiving similar unexpected authentication prompts

How to defend

  • Never approve an MFA prompt you did not personally trigger
  • Move from simple approve or deny push notifications to number matching
  • Report repeated unexpected prompts to security immediately and change your password
  • Enable rate limiting on authentication attempts where available
  • Monitor for unusual volumes of MFA requests tied to a single account

Real-world example

An IT administrator at an Indonesian telecom provider receives a dozen MFA push notifications within a few minutes, late at night, all for a login they did not initiate. Exhausted and assuming it is a glitch, they tap approve on one, unknowingly granting the attacker, who already had their stolen password, access to the corporate network.

How Claro helps

Claro's awareness modules include MFA fatigue scenarios so employees learn to deny and report unexpected authentication prompts instead of approving them out of habit.

Frequently asked questions

Why is MFA fatigue effective against multi-factor authentication?

It does not attack the cryptography behind MFA at all. Instead, it targets the human approval step, wearing the victim down with repeated push notifications until they approve one out of frustration, confusion, or habit.

How is MFA fatigue different from a normal MFA prompt?

A normal prompt appears once, right after you attempt to log in yourself. MFA fatigue involves repeated, unsolicited prompts you did not trigger, sometimes arriving in a rapid burst or at unusual hours, which is the key warning sign.

Does number matching stop MFA fatigue attacks?

Yes, largely. Number matching requires the user to read a code from the login screen and type it into the app, rather than simply tapping approve, which prevents accidental or fatigued approval of a request the user never initiated.

What should I do if I receive unexpected MFA prompts?

Deny every prompt you did not trigger, change your password immediately, and report the activity to your security team. Treat repeated unexpected prompts as a sign your credentials have already been compromised.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo