What Is MFA Fatigue (Push Bombing)?

by

Last Updated:
11 min read
What Is MFA Fatigue (Push Bombing)?

Key Takeaways

  • MFA fatigue attacks cannot begin unless an attacker has already stolen your primary login credentials.
  • This technique relies entirely on cognitive overload and psychological exhaustion, not technical code exploits.
  • Historic breaches at Uber, Cisco, and MGM prove that simple “Approve/Deny” prompts are highly vulnerable to human error.
  • Attackers deliberately flood users with relentless prompts during off-hours to force a reflex approval.
  • To defeat push bombing, organizations must transition to number matching or phishing-resistant FIDO2 (Fast IDentity Online) security keys.

Your phone buzzes at 11:30 PM with a multi-factor authentication (MFA) prompt. You ignore it, but the alerts keep coming, dozens of identical prompts buzzing relentlessly for over an hour. This isn’t a technical glitch; it is an active MFA fatigue attack, also known as push bombing or MFA prompt bombing.

This exact psychological exploit allowed an attacker linked to the Lapsus$ group to breach Uber in September 2022. After purchasing a contractor’s stolen password on the dark web, the threat actor flooded the contractor’s device with constant push notifications. Exhausted, annoyed, and assuming it was a system error, the contractor finally tapped “Approve”. Within minutes, the hacker gained full access to Uber’s internal Slack channels, VPN, and source-code repositories.

For security teams, the lesson is clear. MFA is a foundational security control, but standard “Approve/Deny” prompts are only as secure as the judgment of the exhausted human approving them. Understanding this attack chain is the first step toward building a truly resilient defense.

What Is MFA Fatigue / Push Bombing?

MFA fatigue is a social-engineering technique where an attacker who has obtained stolen corporate credentials floods a target’s device with repeated MFA push requests. The aim is to coerce them into approving a rogue session by exhausting, confusing, or distracting the employee. Eventually, the victim approves the login request simply to make the notifications stop or because they believe it is a technical system error.

The security community categorizes this behavior systematically. The MITRE ATT&CK framework officially classifies this tactic under Technique T1621 (Multi-Factor Authentication Request Generation). It does not exploit a software flaw in your identity management provider. Rather, it treats the human user as the final obstacle to be bypassed using raw volume and persistence.

It is important to separate the terminology from the core threat. Whether your security operations team refers to it as push bombing, prompt spamming, or MFA fatigue, the functional mechanism remains identical. The attack is a post-credential-theft bypass technique. The underlying security architecture works exactly as designed, but the human element is manipulated into rendering that security irrelevant.

How Do Hackers Use MFA Fatigue to Gain Access?

How-Do-Hackers-Use-MFA-Fatigue-to-Gain-Access--

An MFA fatigue attack follows a structured, multi-phase lifecycle. It never occurs in a vacuum. Attackers must lay down groundwork before they can begin sending authentication requests. Below is the typical step-by-step methodology observed in real-world breaches.

Step 1. Credential Theft

An attacker cannot initiate an authentication prompt without first knowing the target’s primary credentials. This phase is step zero. Threat actors harvest these credentials using phishing emails, infostealer malware, or credential stuffing attacks. In many instances, attackers simply buy active login packages directly from dark-web marketplaces. These validated corporate access credentials can sell for as little as $10 to $50 per set, according to dark web threat-intelligence research.

Step 2. The Push Flood

Once the attacker obtains the valid username and password, they enter them into the organization’s login portal. This action automatically triggers a legitimate push notification to the employee’s registered authenticator app. The attacker repeats this action systematically. They often generate dozens of requests in quick succession. These floods are frequently timed during periods of low cognitive attention, such as late at night or during hectic early-morning commutes.

Step 3. The Social Engineering Assist

To increase their chances of success, sophisticated groups couple the digital flood with direct communication. An attacker may initiate a phone call or send an SMS in a targeted impersonation attack, pretending to be an IT helpdesk representative. They will inform the employee that the notifications are part of an ongoing security update or system check. The attacker then instructs the victim to approve the prompt to resolve the issue. This technique, known as vishing, adds a powerful layer of authority to the digital harassment.

Step 4. Approval and Pivot

The moment the victim approves a single notification, the login phase succeeds. The attacker’s web session is instantly validated. With initial access established, they can bypass local controls and move laterally across the corporate network. Once inside, they work to escalate privileges, exfiltrate sensitive files, or deploy devastating ransomware payloads.

Why Is MFA Fatigue an Effective Attack Method?

The core reason this attack remains highly successful is that it is a form of social engineering: it relies on human psychology, not software vulnerabilities. Traditional cybersecurity systems treat human decision-making as a rational, consistent process. In practice, however, cognitive performance degrades rapidly under conditions of stress, high cognitive load, and fatigue.

First, modern professionals experience profound “notification blindness”. The average office worker processes dozens of push notifications on their personal and professional devices every single day. This constant stimulus trains our brains to tap through pop-ups with minimal analytical thought. Over time, the physical action of tapping “Approve” transitions from a conscious security decision to an automated muscle reflex.

Second, attackers exploit timing. Triggering a flood of prompts at 2:00 AM forces the victim to choose between critical thinking and immediate sleep. When a phone vibrates continuously next to an employee’s bed, the fastest path back to rest is to comply with the device’s prompt. Behavioral analysis proves that human defenses degrade under such pressure.

The telemetry validates these physiological insights. According to telemetry released by Microsoft, their automated threat detection engines logged more than 382,000 MFA fatigue attempts over a single 12-month period. Shockingly, their data revealed that roughly 1% of all targeted users approved the very first unexpected push notification they received on their screen.

Real-World Breaches: How MFA Fatigue Caused Historic Damage

We do not have to theorize about the damage these attacks can do. Over the past few years, some of the world’s most recognizable brands have been brought to their knees because a single employee got tired of their phone buzzing.

Uber (September 2022)

In this incident, an attacker purchased a contractor’s credentials on the dark web after they were harvested via infostealer malware. The attacker logged in repeatedly, generating an hour-long storm of push notifications. To break the deadlock, the hacker messaged the contractor on WhatsApp, posing as an Uber IT administrator. The contractor finally approved the request, giving the Lapsus$ threat group access to the internal network.

Cisco (2022)

The threat actors behind the Cisco breach utilized a highly structured combination of vishing and prompt spamming. First, they extracted primary login credentials from an employee’s browser profiles. Next, they initiated a series of push prompts. While the prompts were active, the attackers placed voice calls impersonating trusted support desks, persuading the employee to approve the connection. This allowed the actors to establish an authenticated VPN session.

Lapsus$ vs. Tech Giants (2022)

During a broader campaign, the Lapsus$ group turned this social engineering technique into a standard operating procedure. They deployed similar push-bombing mechanisms to infiltrate Microsoft, Okta, Nvidia, and Samsung. By pairing the technical prompt generation with direct, high-pressure communication pretending to be IT units, they bypassed perimeter MFA systems across multiple enterprises within months.

MGM Resorts & Caesars Entertainment (2023)

In late 2023, the threat group Scattered Spider illustrated a dangerous evolution of this attack. The hackers initiated a targeted campaign by conducting reconnaissance on LinkedIn, then phoned the corporate IT helpdesk. They successfully impersonated high-level employees, convincing helpdesk staff to reset the MFA profiles on privileged accounts. They then used push bombing to secure the authenticated login. While Caesars reportedly paid a $15 million ransom, as widely reported by outlets including Reuters and the BBC, MGM opted to rebuild, sustaining massive operational and financial losses.

Marks & Spencer (April 2025)

The exact same playbook was deployed against retail giant Marks & Spencer in early 2025. Members of the Scattered Spider threat group compromised primary credentials, tricked helpdesk personnel, and executed an aggressive MFA fatigue campaign. The resulting access was used to deploy DragonForce ransomware. The attack disrupted operations at roughly 1,049 retail stores, contributing to an immediate 7% drop in the company’s share price, according to contemporaneous BBC and Reuters coverage.

MFA Fatigue by the Numbers

For a long time, many security professionals treated prompt spamming as a rare edge case. However, industry incident data from 2025 and 2026 reveals it has graduated into a mainstream cybercriminal tool:

  • According to the 2025 Verizon Data Breach Investigations Report (DBIR), prompt bombing appeared in roughly 14% of all analyzed social-engineering incidents globally.
  • The 2025 DBIR noted that prompt bombing succeeded in more than 20% of social-engineering attacks targeting public sector organizations specifically.
  • Looking specifically at attacks targeting Microsoft 365 environments, the DBIR found that MFA interrupts (including fatigue attacks) represented 22% of all successful MFA bypass attempts. Token theft, a related technique, accounted for 31% of bypass techniques.
  • Multiple 2025 incident-response reports found that approximately 79% of investigated business email compromise (BEC) victims already had MFA enabled on their systems, which proved that basic MFA setups can be bypassed.
  • Despite the clear risk, a Cisco Duo-sponsored enterprise survey indicated that only 19% of organizations have fully deployed phishing-resistant authentication methods like FIDO2 keys across their entire employee base.

Which MFA Methods Are Most (and Least) Vulnerable?

Not all multi-factor authentication methods are created equal. If your company’s security policy treats all secondary verification forms the same, you have a critical blind spot. Below is a practical breakdown of how different authentication protocols perform against push bombing attacks.

Authentication MethodVulnerability LevelHow It Handles Push Bombing
Approve/Deny Push NotificationsHighRelies on a single tap. High exposure to cognitive fatigue, accidental clicks, and notification spamming.
SMS & Voice One-Time Passcodes (OTP)HighVulnerable to SIM-swapping, interception, or social-engineering phone calls designed to harvest the code.
Number Matching PushMediumRequires the user to enter numbers displayed on the login page. Halts blind clicks, but can be bypassed via vishing.
FIDO2 / Passkeys / Hardware KeysPhishing-ResistantCryptographically binds the authentication session to the browser domain. Cannot be bypassed via remote prompts.

How to Defend Against MFA Fatigue and Push Bombing

How-to-Defend-Against-MFA-Fatigue-and-Push-Bombing-

Defeating push bombing does not require you to scrap your identity infrastructure. It does, however, require you to build intelligent guardrails. By implementing a layered defense policy, you can systematically neutralize the technical and psychological vectors of this attack.

1. Move to Number Matching or Phishing-Resistant MFA

If you cannot move off standard mobile app pushes immediately, turn on number matching. This feature is supported natively in Microsoft Entra ID, Okta, and Cisco Duo. When enabled, a user cannot just tap “Approve”. They must look at a sequence of digits displayed on the initiating login screen and type them into their authenticator app. This simple friction point shuts down blind, reflexive clicking entirely. For your highest-privilege accounts, prioritize migrating to FIDO2/WebAuthn security keys or passkeys, which remove the tap-to-approve step altogether.

2. Rate-Limit and Cap Push Notifications

Do not allow your authentication servers to process endless requests. Configure your identity provider (IdP) policies to lock accounts or initiate temporary cooldown periods after three to five denied or ignored push notifications. If an attacker cannot generate more than a few prompts before locking the profile, the psychological fatigue vector disappears.

3. Harden Your IT Helpdesk

The spectacular breaches at MGM and Caesars were not software failures. They were helpdesk compromises. Your support staff must use rigorous identity-verification protocols before resetting an employee’s MFA configuration. Implement mandatory callbacks to pre-registered phone numbers, require secondary approval from managers, or verify identities in person before changing security settings on a privileged account.

4. Alert on Consecutive Denials

Treat denied authentication notifications as a serious signal, not background noise. If an employee taps “Deny” multiple times in a short window, your security operations center (SOC) should receive an automated alert. This action signals that an attacker has already bypassed the primary password layer and is actively trying to break the secondary defensive line.

5. Cut Off the Attack at Its Real Starting Point: Credential Theft

Let’s be direct: push bombing cannot occur unless an attacker has already stolen your username and password. While email protocols do not directly control MFA infrastructure, securing your communication layer prevents the initial compromise. The vast majority of corporate credentials are stolen through phishing emails that impersonate internal platforms or trusted partners, often generated using turnkey email spoofing as a service kits sold on underground forums.

Enforcing security protocols like DMARC (Domain-based Message Authentication, Reporting, and Conformance) at a policy of p=reject is critical. Implementing DMARC alongside SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) prevents malicious actors from spoofing your corporate domains to harvest passwords from employees. By blocking impersonation emails, you materially reduce the primary vectors used in “Step Zero” of the attack lifecycle.

6. Train Employees on the “Deny and Report” Response

Do not limit your cybersecurity training to boring, generic slideshows. Conduct simulated MFA fatigue scenarios. Teach employees that their phone buzzing with unexpected prompts is a sign of compromise, not a system error. Create a simple, friction-free mechanism for employees to “Deny and Report” suspicious activity directly to security teams with a single tap.

MFA Fatigue vs. Other MFA Bypass Techniques

While prompt spamming is incredibly effective, it is only one tool in the modern cybercriminal’s arsenal. To protect your organization, you must understand how this threat compares to other common authentication bypass techniques.

  • Adversary-in-the-Middle (AiTM) Phishing: Unlike MFA fatigue, which relies on a user’s compliance, AiTM setups deploy a proxy server between the victim and the legitimate login portal. The proxy captures both the user’s primary credentials and the validated session cookie in real time, bypassing MFA completely without needing to spam the victim’s device.
  • SIM Swapping: In this attack, the threat actor socially engineers a mobile carrier into transferring the victim’s phone number to a rogue SIM card. This allows them to intercept SMS-based one-time codes, targeting cellular networks rather than exploiting push notifications.
  • Session Token Theft: This technique utilizes specialized infostealer malware or compromised browser extensions to extract active session tokens directly from local memory. This lets the attacker hijack an active corporate session, bypassing the login portal and secondary verification phases entirely.

It is important to understand that threat actors do not limit themselves to a single method. Advanced attack groups often blend these techniques. For example, a group might use phishing to capture credentials, attempt an AiTM bypass, and then fall back to helpdesk-focused vishing and push spamming if initial attempts fail.

Defeating MFA Fatigue: The Path Forward

Let’s face it: push-based multi-factor authentication was designed to be fast and frictionless, but MFA fatigue and push bombing prove that ease of use has become its biggest vulnerability. The high-profile compromises of Uber, Cisco, MGM, and Marks & Spencer prove that relying on a human user to make the right choice during an ongoing attack is a major security risk.

To keep your organization safe, you must move beyond basic “Approve/Deny” setups. Implementing number matching and rate limiting on push notifications is a crucial first step, but securing your entry points is equally vital. By combining phishing-resistant authentication methods with rigorous domain security protocols, you can defend your users at every stage of the threat cycle.

Ready to secure your domain and stop credential harvesting at its source? Start by assessing your email authentication setup today. Visit our guides on credential harvesting to understand how hackers target your passwords, and discover how the PowerDMARC Analyzer can keep fraudulent phishing emails out of your employees’ inboxes.

Frequently Asked Questions

What is MFA fatigue in simple terms?

MFA fatigue is a cyberattack where a hacker who already knows your password repeatedly triggers authentication requests on your phone. They flood your device with “Approve” notifications, hoping you will eventually click it out of sheer annoyance, confusion, or to make the notifications stop buzzing.

Is MFA fatigue the same thing as MFA bombing or push bombing?

Yes, these terms describe the exact same attack technique. Whether security professionals call it MFA fatigue, prompt spamming, MFA bombing, or push bombing, the underlying methodology remains the same. Attackers flood a victim’s device with repeated authentication prompts until they yield.

How do hackers use MFA fatigue to gain access?

First, hackers steal your credentials via phishing, infostealer malware, or dark-web marketplaces. Next, they attempt to log in to your account repeatedly, triggering endless push prompts on your phone. Once you tap “Approve” out of exhaustion, the attacker is instantly authenticated into your corporate network.

Why is MFA fatigue an effective attack method?

It is highly effective because it exploits human psychology instead of technical software bugs. It leverages common cognitive conditions like notification fatigue, distraction, and late-night exhaustion, transforming a standard security check into a persistence game that the attacker only needs to win once.

Can DMARC or email authentication prevent MFA fatigue attacks?

DMARC cannot directly stop push notifications once an attacker has your credentials. However, it blocks the spoofed phishing emails that attackers use to harvest those credentials in the first place. This systematically shuts down the critical “Step Zero” required for the attack to occur.

What is the single most effective defense against push bombing?

The absolute strongest defense is migrating to passwordless, phishing-resistant multi-factor authentication, such as FIDO2 hardware security tokens or platform passkeys. These technologies cryptographically bind logins to your browser session, neutralizing remote push bombing and credential theft entirely.

mfa fatigue