Skip to main content

Security

What Is an MFA Fatigue Attack?

Share:

An MFA fatigue attack is a social engineering technique in which an attacker repeatedly sends multi-factor authentication requests to a victim’s device until the victim approves one out of frustration, confusion, or habit. It is also known as MFA bombing, MFA spamming, or prompt bombing.

To launch this attack, the attacker first obtains valid login credentials, typically a username and password. Multi-factor authentication serves as an important security layer, and MFA fatigue attacks aim to bypass it by manipulating users rather than breaking the technology itself.

How MFA fatigue attacks work

MFA fatigue attacks usually follow a simple scenario. First, the attacker steals or buys credentials. They may obtain a username and password through phishing, credential stuffing, brute-force attacks, infostealing malware, or by purchasing compromised credentials on the dark web.

Then, the attacker uses the stolen credentials to log in. Each login attempt triggers a multi-factor authentication request on the user’s authentication device.

The user receives repeated MFA prompts, which can create confusion, annoyance, or a false sense of urgency. In some cases, the attacker also contacts the victim by phone or chat, acting as a member of the IT team, and asks them to approve the request.

Once the user approves the request, the attacker gains access to their account. They may access sensitive systems, move laterally, steal data, or deploy malware.

Why MFA fatigue attacks are effective

MFA fatigue attacks work because they exploit the human element, not a technical flaw in multi-factor authentication. The attacker relies on pressure, repetition, and user behavior to turn a security measure into an entry point.

Push-based MFA is especially vulnerable to MFA fatigue attacks as it relies on a simple approve/deny flow. Employees may approve such prompts without double-checking, creating a habit of automatic approval. It happens especially often when employees are overworked, distracted, or under time pressure.

In some cases, employees may not fully understand security procedures or how to respond to unexpected prompts, increasing the chance of mistakes. Others may knowingly bypass or ignore security policies to avoid delays and maintain productivity, unintentionally creating opportunities for attackers.

How to prevent MFA fatigue attacks

There are several measures for stronger authentication and MFA fatigue attack prevention.

Switch to phishing-resistant MFA

Adhere to phishing-resistant authentication methods, such as number-matching prompts, FIDO 2 authentication, Web Authentication hardware keys, or certificate-based authentication. These methods reduce or remove the simple approve/deny flow that attackers abuse in MFA fatigue attacks.

Rate-limit and throttle MFA requests

Set a limit on the number of push notifications sent during a single login session. You can also lock accounts or require additional verification after repeated failed attempts.

Apply least privilege

Restrict what each account can access, especially for privileged users, vendors, contractors, and administrators. If an attacker compromises one account, least privilege helps limit lateral movement and reduce the blast radius.

Educate users

Teach employees to never approve unsolicited MFA prompts. They should immediately report any repeated authentication requests they didn’t initiate to the IT or security team. Regular, repeated cybersecurity training reinforces these habits, helping employees stay alert and respond confidently when suspicious MFA requests occur.

Monitor authentication logs

Flag anomalies such as high-frequency login attempts, unusual geolocation, new devices, off-hours MFA requests, and repeated failed authentication events. These signals can help your security team detect an MFA fatigue attack before the attacker gains initial access or spreads further inside your systems.

Syteca is a privileged access management (PAM) platform with identity threat detection and response (ITDR) that helps you control access to critical systems and detect suspicious activity across your IT environment. With granular access controls, secure credential management, user activity monitoring, session recording, and real-time alerts, Syteca helps you reduce the impact of stolen credentials and unauthorized access attempts.

Syteca also helps your organization limit what a compromised account can do after authentication. By applying least privilege, monitoring privileged sessions, and recording user activity, you can investigate suspicious activity, respond faster to security events, and reduce the likelihood that a single approved MFA prompt will trigger a large security incident.

Want to try Syteca? Request access
to the online demo!

See why clients from 70+ countries already use Syteca.

FAQ

Your organization may be under an MFA fatigue attack if employees report repeated multi-factor authentication prompts when they are not trying to log in. Especially, if the login attempts occur outside normal working hours, from unfamiliar locations, or across multiple user accounts.

Your employees should not approve these requests. They should deny the prompt, change their password from a trusted device, and report the incident to the IT or security team immediately. If someone contacts them claiming to be from IT and asks them to approve an MFA prompt, they should verify the request through an authorized channel before taking any action.

Share:

Content