MFA Fatigue Attack
Abbreviation: MFA
Pronunciation: M-F-A fuh-TEEG uh-TAK
Also known as: Push bombing, MFA prompt bombing, MFA
Definition
An MFA fatigue attack repeatedly sends authentication prompts or approval requests to pressure, confuse, or trick a user into approving one, often after the attacker has obtained the password. It targets push-based approval behavior and is less effective against phishing-resistant authenticators that cryptographically bind authentication to the legitimate service. Operationally, teams should prefer phishing-resistant MFA, use number matching and contextual prompts where push remains, limit request frequency, and detect impossible patterns.
Overview
An MFA fatigue attack repeatedly sends authentication prompts or approval requests to pressure, confuse, or trick a user into approving one, often after the attacker has obtained the password.
MFA Fatigue Attack is closely connected to Hardware Security Key, Passwordless Authentication, and Identity Threat Detection and Response (ITDR). It targets push-based approval behavior and is less effective against phishing-resistant authenticators that cryptographically bind authentication to the legitimate service.
Operational implementation should prefer phishing-resistant MFA, use number matching and contextual prompts where push remains, limit request frequency, detect impossible patterns, educate users to report prompts, and secure help-desk recovery.
The principal failure modes include prompt bombing, social engineering, accidental approval, compromised passwords, alert desensitization, attacker calls pretending to be support, and weak fallback authentication.
Useful measures include phishing-resistant enrollment, denied unsolicited prompts, prompt-burst detections, user reports, and accounts compromised after MFA approval.
Operationally, teams should prefer phishing-resistant MFA, use number matching and contextual prompts where push remains, limit request frequency, and detect impossible patterns. Key risks include prompt bombing, social engineering, accidental approval, and compromised passwords.
Assessment of MFA Fatigue Attack should trace MFA fatigue attack repeatedly sends authentication prompts or approval requests to pressure, confuse, or trick a user into approving one, often after the attacker has obtained the password from prerequisite and entry point through observable impact on the affected service. A theoretical weakness or scanner result involving approval requests to pressure, confuse, and trick a user into approving one should not be reported as exploitation without corroborating logs, transactions, or configuration evidence. Prevention, detection, containment, and recovery for the MFA Fatigue attack path should be tested against the architecture associated with approval requests to pressure, confuse, and trick a user into approving one.
Key Takeaway
An MFA fatigue attack repeatedly sends authentication prompts or approval requests to pressure, confuse, or trick a user into approving one, often after the attacker has obtained the password.
Sources
- More than a Password: Multifactor Authentication — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Phishing Guidance: Stopping the Attack Cycle at Phase One — Cybersecurity and Infrastructure Security Agency (2026-08-03)
- Digital Identity Guidelines: Authentication and Authenticator Management, NIST SP 800-63B-4 — NIST (2026-08-03)