An MFA fatigue attack is a social engineering technique where attackers flood a target’s device with repeated multi-factor authentication push notifications, betting that the user will eventually approve one just to make the alerts stop. The attacker already holds valid credentials, usually stolen through phishing or purchased from dark web markets. The attack exploits human psychology, not technical weaknesses. MITRE ATT&CK classifies this technique as T1621: Multi-Factor Authentication Request Generation. According to CISA and the FBI’s advisory on the Scattered Spider group, push bombing is a confirmed, active social-engineering method used by sophisticated threat actors today.
Most business owners I speak with assume MFA is a complete solution. It isn’t. MFA is a strong layer, but it has a gap: the human being receiving the prompt. That gap is exactly what MFA fatigue attacks exploit. And the painful truth is, it works more often than anyone wants to admit.
What Is an MFA Fatigue Attack?
An MFA fatigue attack, also called MFA bombing, push bombing, or prompt bombing, targets the user rather than the authentication system itself, making it one of the most psychologically effective attack methods in active use.
Standard MFA stops most opportunistic attackers cold. It adds a second verification step after a password, requiring something the user has, like a phone or hardware key. But push-based MFA has an inherent design flaw: the user decides whether to approve. Flood someone with enough prompts, and approval becomes the path of least resistance.
The ioSENTRIX social engineering assessments found that approval rates for push bombing range from 15 to 25% when the attack continues for several hours. That is not a fringe outcome. One in five employees, in real-world testing, will eventually tap “approve.”

MITRE ATT&CK T1621 formally documents this technique under the category of credential access. It sits alongside phishing and credential stuffing precisely because MFA fatigue attacks are now a standard tool in the attacker’s kit, not an exotic outlier.
How an MFA Fatigue Attack Works: The Attack Stages
An MFA fatigue attack follows a predictable sequence that begins long before the push notifications appear, giving defenders multiple points to break the chain.
Credential acquisition comes first. Without a valid username and password, an attacker cannot trigger MFA prompts at all. According to Verizon’s 2025 DBIR research on credential stuffing, stolen credentials appeared in 22% of all breaches in 2025, making them the most common entry point for identity-based attacks. Attackers obtain credentials through phishing, credential stuffing, infostealer malware, or simply buying them from dark web markets.

The numbered stages below reflect the full attack lifecycle:
- Credential acquisition: Attacker obtains a valid username and password through phishing, infostealer malware, or a dark web purchase.
- Authentication attempt: Attacker logs in with the stolen credentials, triggering the MFA prompt mechanism.
- Push notification flooding: The attacker initiates repeated authentication requests, sending a continuous stream of MFA push notifications to the victim’s device.
- User fatigue and habituation: The target, overwhelmed by alerts at all hours, eventually approves a prompt, sometimes accidentally, sometimes out of frustration, sometimes after a follow-up social engineering call claiming to be IT support.
- Access granted and persistence: The attacker logs in, establishes persistence, and begins lateral movement, data exfiltration, or ransomware deployment.
Stage four is where human psychology becomes the attack vector. Cognitive load, habituation, and the simple desire to stop an annoying alert combine to make even security-conscious users vulnerable. This is not a failure of intelligence. It is a failure of system design.
Why MFA Fatigue Attacks Are So Effective
MFA fatigue attacks succeed because they weaponize human behavior, not software bugs, and no patch can fix a person’s instinct to stop an irritating notification.
Cognitive load is the core problem. When a phone buzzes repeatedly with MFA prompts, especially at night or during a busy workday, the brain starts treating the alerts as noise. Habituation kicks in. The user stops reading the notification carefully and starts looking for the fastest way to make it stop. That fastest way is often “approve.”
Social engineering often amplifies the attack. Scattered Spider, the threat group behind several high-profile breaches, pairs push bombing with phone calls. An attacker poses as IT support and tells the employee they are experiencing a “system issue” that requires MFA confirmation. The employee has already been primed by twenty alerts. The call provides the final push.
The numbers back this up. Okta’s Secure Sign-In Trends Report from January 2025 found that MFA adoption reached 70% of workforce users. That is a real improvement. But adoption does not equal immunity. The 70% using MFA still face this risk if they are using push notifications without additional controls.
Real-World MFA Fatigue Attack Examples
The Uber breach in September 2022 is the clearest documented example of an MFA fatigue attack succeeding against a major organization, and it came down to one contractor approving one WhatsApp message after a wave of push notifications.
The Lapsus$ group obtained an Uber contractor’s credentials, likely through a third-party data breach. They then triggered repeated MFA push notifications. When the contractor stopped responding to the prompts, the attacker messaged them directly on WhatsApp, claiming to be from Uber IT support, and asked them to approve the request. The contractor did. Lapsus$ was inside Uber’s network within minutes.
Cisco suffered a similar attack in 2022. An attacker accessed a Cisco employee’s personal Google account, which contained saved corporate credentials. Push bombing followed. The employee eventually approved a prompt. Cisco contained the breach, but the attacker had already accessed internal systems.
These were not small companies with limited security budgets. Both had mature security teams. The attack worked because the weak point was never the technology. It was the person holding the phone.
CISA and the FBI have publicly confirmed that Scattered Spider continues to use push bombing as a primary technique according to their updated advisory on Scattered Spider’s social-engineering methods. The group targets large organizations, but the technique scales down easily. Any business using push-based MFA is a viable target.
The Business Impact of MFA Fatigue Attacks
A successful MFA fatigue attack does not just unlock one account. It opens a door to the entire network, and the financial and reputational consequences can be severe.
Once inside, attackers move fast. They establish persistence, escalate privileges, and begin exfiltrating data or deploying ransomware. A single approved MFA prompt can trigger a breach that takes months to discover and years to recover from.
The financial scale of identity-driven attacks is significant. The FBI’s Internet Crime Complaint Center 2025 Annual Report recorded 1,008,597 complaints and losses exceeding $20.877 billion, a 26% rise from 2024. Not all of those stem from MFA fatigue specifically, but credential-based access is a primary enabler of the fraud categories driving those losses.
For SMEs, the impact is disproportionate. A breach that a large enterprise can absorb, through legal teams, PR resources, and crisis management budgets, can be existential for a 50-person firm. Client trust takes years to build and hours to destroy.
How to Detect MFA Fatigue Attacks
MFA fatigue attacks leave detectable signals in authentication logs, and catching them early depends entirely on whether anyone is actually monitoring those logs.
Most organizations generate MFA log data. Few act on it in real time. The patterns that indicate an ongoing push bombing attempt are not subtle: a single user account triggering dozens of MFA requests in a short window, from an unfamiliar IP address or geography, at an unusual hour, is a strong signal something is wrong.
Detection strategies worth building into your security monitoring:
- Monitor MFA prompt frequency: Set thresholds that alert when a user receives more than five to ten MFA requests in a short timeframe. Most platforms, including Microsoft Authenticator, Duo, and Okta, offer logging and alerting capabilities.
- Track authentication geography: A UK-based employee receiving MFA prompts from a login attempt originating in Eastern Europe is a clear anomaly.
- Correlate failed logins with prompt volume: Repeated failed logins followed by a surge in MFA requests is a textbook push bombing pattern.
- Use behavioral analytics: Modern SIEM platforms can baseline normal authentication behavior and flag deviations automatically.
- Create user reporting channels: Train employees to report unexpected MFA prompts immediately, via a dedicated Slack channel, email alias, or phone line. Fast reporting turns a potential breach into a contained incident.
Google’s M-Trends 2026 report found that interactive voice-based social engineering rose to the second most common initial access vector in 2025. That matters here because voice social engineering often runs alongside push bombing, as seen in the Uber case. If your team reports suspicious phone calls claiming to be IT support, treat it as a potential MFA fatigue attack in progress.
How to Prevent MFA Fatigue Attacks
Phishing-resistant MFA, including FIDO2 security keys and passkeys, is the most effective technical control against MFA fatigue attacks because it removes the push notification mechanism entirely.
Push-based MFA is the problem. The solution is either to make push approval harder to fake, or to replace push entirely with a method that cannot be bombed.
Technical Controls That Work
Number matching is the first fix to deploy if you cannot move away from push notifications immediately. With number matching enabled, the user must enter a code displayed on the login screen into the authenticator app, rather than simply tapping “approve.” An attacker flooding a device with prompts cannot get the right code without access to the user’s screen. Microsoft has made number matching the default in Microsoft Authenticator. If you haven’t confirmed it’s enabled, check today.

Rate limiting MFA prompts adds a second layer. Configure your identity provider to lock or delay authentication attempts after a threshold of failed or unanswered MFA requests. This cuts the flooding mechanism off at the source.
FIDO2 security keys from providers like YubiKey deliver phishing-resistant MFA that cannot be push-bombed. There is no notification to approve. The user inserts or taps a physical key. No key, no access. According to Microsoft’s 2025 Digital Defense Report, phishing-resistant MFA can block over 99% of identity-based attacks. That number should settle any internal debate about whether the migration is worth the effort.

Passkeys are gaining ground fast. The FIDO Alliance’s State of Passkeys 2026 report found that 68% of organizations globally are deploying, piloting, or rolling out passkeys for employee authentication, with an estimated 5 billion passkeys now in active use worldwide. If your identity provider supports passkeys, test the rollout with a pilot group now.

Conditional access policies add a further control layer. Require device compliance checks, enforce trusted network access, and block authentication from unrecognized devices or high-risk locations.
Human Controls That Are Non-Negotiable
Security awareness training is not optional when MFA fatigue attacks rely on human behavior. Employees need to know two things clearly: they should never approve an MFA prompt they did not initiate, and they should report unexpected prompts immediately, no matter how many arrive.
Run simulated push bombing drills alongside phishing simulations. Employees who have experienced a simulated attack respond better in a real one. For a broader look at how to build effective employee security habits, the guidance on cybersecurity awareness training covers the full framework.
Pair training with a clear, frictionless reporting process. If reporting an unusual MFA prompt requires filling out a ticket, staff won’t do it. Make it a one-tap message to a monitored channel.
Building a Layered Defense Against MFA Bombing
No single control stops every MFA fatigue attack, which is why layered defense, combining technical controls, behavioral analytics, and trained users, is the only approach that holds up under real-world conditions.
The table below maps each control to what it actually prevents:
| Control | What It Stops | Priority |
|---|---|---|
| Number matching | Blind prompt approval without code verification | Deploy immediately |
| Rate limiting MFA prompts | Sustained push notification flooding | Deploy immediately |
| FIDO2 / passkeys (phishing-resistant MFA) | All push-based attack vectors | Target state |
| Conditional access policies | Logins from unrecognized devices or locations | Deploy alongside MFA |
| Security awareness training | User-level approval of illegitimate prompts | Ongoing |
| MFA prompt monitoring and SIEM alerts | Attacks in progress, before access is granted | Ongoing |
Start with number matching and rate limiting. Both are configuration changes in your existing identity platform, not new purchases. Then build toward FIDO2 security keys or passkeys as your long-term target state for phishing-resistant MFA.
Do not treat user training as a one-time checkbox. MFA fatigue attacks work because attackers have figured out that humans are the most persistent vulnerability in any security stack. The Uber breach, the Cisco incident, and the ongoing activity of groups like Lapsus$ all prove the same point.
For a broader look at how credential theft feeds into MFA fatigue attacks and other identity-based threats, the guidance on phishing attack prevention covers the credential acquisition stage in detail. Stopping credential theft upstream reduces the pool of accounts that can be targeted by push bombing downstream.
Train your people. Enable number matching today. Start a passkey pilot this quarter. The businesses that get hit by MFA bombing are not unlucky. They are the ones that assumed MFA was enough without asking whether the type of MFA they deployed was still fit for purpose.


