First, What Is MFA Fatigue?
At its core, MFA fatigue is a social engineering attack that exploits human nature, not a technological flaw. It’s also known as MFA bombing or push notification spam. The attack begins after a criminal has already stolen a user's password, often through
phishing or by buying it on the dark web. When the attacker tries to log in, the multi-factor authentication system does its job and sends a push notification to the real user's phone for approval. The attacker can't get in without that approval. So, they don't try just once. They try again, and again, and again, deliberately spamming the user with a flood of login approval requests.
The Annoyance Is the Attack
The goal of MFA fatigue is to wear you down. Attackers are betting that a user will get so annoyed, confused, or distracted by the constant buzzing on their phone that they’ll eventually hit 'Approve' just to make it stop. In some cases, the attacker might even call or message the target, posing as IT support and telling them to approve the prompt to fix a supposed technical issue. This isn't theoretical; it's a proven tactic. The notorious Lapsus$ hacking group used this exact method in a high-profile 2022 breach against Uber, where an employee was bombarded with requests for over an hour before finally giving in. The attack works by weaponizing the very notification that’s meant to protect you.
How to Explain It: Use an Analogy
Technical definitions can make people’s eyes glaze over. To make the threat feel real during Cybersecurity Awareness Month, use a simple analogy. Explain that an MFA fatigue attack is like a stranger repeatedly and aggressively ringing your digital doorbell. They are already standing at your door because they have one key (your password), but they need you to buzz them in. The first few times, you ignore it. But after the 50th ring, you might give in just to get some peace and quiet, assuming it must be a mistake or someone you know. The key is to train employees to see a flood of unexpected prompts not as an annoyance, but as a clear signal that someone is actively trying to break into their account.
The Golden Rule: If You Didn't Initiate, Deny
The most critical takeaway for employees must be a simple, memorable action plan. The golden rule should be: 'If you didn't just try to log in, never, ever approve the request.' Instead, they should immediately hit 'Deny.' The second step is just as important: report it. Employees need a clear and easy way to notify your IT or security team about the suspicious activity. Reporting unusual MFA activity is often the fastest way for security teams to detect that an account is being targeted. After denying and reporting, the user should change their password immediately, as the attack proves their current one has been compromised.
Beyond Awareness: Building Stronger Defenses
While user education is the first line of defense, companies can also implement stronger technical controls. One of the most effective is enabling 'number matching' in authenticator apps. This requires the user to type a unique number displayed on the login screen into their app, rather than simply tapping 'Approve,' which makes accidental approval almost impossible. Other powerful defenses include rate-limiting the number of MFA prompts an account can receive in a short period and deploying phishing-resistant MFA methods like FIDO2 security keys for high-value accounts. These steps shift the burden from relying solely on human vigilance to building a more resilient security system.













