An MFA fatigue attack is a social engineering technique in which an attacker repeatedly sends multi-factor authentication requests to a victim’s device until the victim approves one out of frustration, confusion, or habit. It is also known as MFA bombing, MFA spamming, or prompt bombing.
To launch this attack, the attacker first obtains valid login credentials, typically a username and password. Multi-factor authentication serves as an important security layer, and MFA fatigue attacks aim to bypass it by manipulating users rather than breaking the technology itself.
How MFA fatigue attacks work
MFA fatigue attacks usually follow a simple scenario. First, the attacker steals or buys credentials. They may obtain a username and password through phishing, credential stuffing, brute-force attacks, infostealing malware, or by purchasing compromised credentials on the dark web.
Then, the attacker uses the stolen credentials to log in. Each login attempt triggers a multi-factor authentication request on the user’s authentication device.
The user receives repeated MFA prompts, which can create confusion, annoyance, or a false sense of urgency. In some cases, the attacker also contacts the victim by phone or chat, acting as a member of the IT team, and asks them to approve the request.
Once the user approves the request, the attacker gains access to their account. They may access sensitive systems, move laterally, steal data, or deploy malware.
Why MFA fatigue attacks are effective
MFA fatigue attacks work because they exploit the human element, not a technical flaw in multi-factor authentication. The attacker relies on pressure, repetition, and user behavior to turn a security measure into an entry point.
Push-based MFA is especially vulnerable to MFA fatigue attacks as it relies on a simple approve/deny flow. Employees may approve such prompts without double-checking, creating a habit of automatic approval. It happens especially often when employees are overworked, distracted, or under time pressure.
In some cases, employees may not fully understand security procedures or how to respond to unexpected prompts, increasing the chance of mistakes. Others may knowingly bypass or ignore security policies to avoid delays and maintain productivity, unintentionally creating opportunities for attackers.
How to prevent MFA fatigue attacks
There are several measures for stronger authentication and MFA fatigue attack prevention.
Switch to phishing-resistant MFA
Adhere to phishing-resistant authentication methods, such as number-matching prompts, FIDO 2 authentication, Web Authentication hardware keys, or certificate-based authentication. These methods reduce or remove the simple approve/deny flow that attackers abuse in MFA fatigue attacks.
Rate-limit and throttle MFA requests
Set a limit on the number of push notifications sent during a single login session. You can also lock accounts or require additional verification after repeated failed attempts.
Apply least privilege
Restrict what each account can access, especially for privileged users, vendors, contractors, and administrators. If an attacker compromises one account, least privilege helps limit lateral movement and reduce the blast radius.
Educate users
Teach employees to never approve unsolicited MFA prompts. They should immediately report any repeated authentication requests they didn’t initiate to the IT or security team. Regular, repeated cybersecurity training reinforces these habits, helping employees stay alert and respond confidently when suspicious MFA requests occur.
Monitor authentication logs
Flag anomalies such as high-frequency login attempts, unusual geolocation, new devices, off-hours MFA requests, and repeated failed authentication events. These signals can help your security team detect an MFA fatigue attack before the attacker gains initial access or spreads further inside your systems.
Syteca is a privileged access management (PAM) platform with identity threat detection and response (ITDR) that helps you control access to critical systems and detect suspicious activity across your IT environment. With granular access controls, secure credential management, user activity monitoring, session recording, and real-time alerts, Syteca helps you reduce the impact of stolen credentials and unauthorized access attempts.
Syteca also helps your organization limit what a compromised account can do after authentication. By applying least privilege, monitoring privileged sessions, and recording user activity, you can investigate suspicious activity, respond faster to security events, and reduce the likelihood that a single approved MFA prompt will trigger a large security incident.
Want to try Syteca? Request access
to the online demo!
See why clients from 70+ countries already use Syteca.
FAQ
An MFA fatigue attack is a social engineering attack in which an attacker repeatedly sends multi-factor authentication prompts to a user’s device until the user approves one out of frustration, confusion, or fatigue. Attackers use this technique after they have already obtained valid login credentials and need the user to confirm the additional authentication factor.
Phishing is a broader social engineering technique used to trick people into revealing sensitive information, such as passwords, payment details, or one-time codes. Attackers often use fake emails, websites, messages, or calls to make the victim believe the request is legitimate.
An MFA fatigue attack is more specific. In this attack, the attacker already has the victim’s username and password and repeatedly triggers multi-factor authentication prompts until the victim approves one.
Your organization may be under an MFA fatigue attack if employees report repeated multi-factor authentication prompts when they are not trying to log in. Especially, if the login attempts occur outside normal working hours, from unfamiliar locations, or across multiple user accounts.
Your employees should not approve these requests. They should deny the prompt, change their password from a trusted device, and report the incident to the IT or security team immediately. If someone contacts them claiming to be from IT and asks them to approve an MFA prompt, they should verify the request through an authorized channel before taking any action.