The Annoyance That Became a Gateway
Multi-factor authentication (MFA) is one of the most effective security tools we have. It’s the digital equivalent of showing your ID after using your key. But its greatest strength—the push notification sent to your phone—has been turned into a weapon
against us. This is MFA fatigue. At its core, it's a social engineering attack where a bad actor, who has already stolen your password, repeatedly tries to log in as you. This triggers a relentless barrage of “Approve/Deny” notifications on your phone, sometimes dozens in a row. The goal isn't to break the technology; it’s to break your patience. Attackers are betting that out of annoyance, confusion, or simple habit, you’ll eventually just tap “Approve” to make the noise stop. And just like that, they’re in.
Weaponizing the 'Deny' Button
High-profile breaches at companies like Uber and Cisco prove this isn't a theoretical problem. In the Uber incident, an attacker spammed a contractor with MFA prompts for over an hour. The attacker then took it a step further, contacting the employee on another platform and pretending to be from the IT department, instructing them to approve the request to resolve the issue. This combination of technical spamming and classic social engineering is devastatingly effective. It exploits a fundamental human reaction to persistent digital noise. When an employee is focused on a deadline or simply trying to get through their day, a constant stream of alerts feels like a system glitch, not a sophisticated attack. This turns what should be a moment of security into a moment of high-pressure vulnerability.
More Than Just a 'User Problem'
For too long, the response to a successful MFA fatigue attack has been to blame the user. But that misses the point entirely. These attacks don’t just prey on a single person’s momentary lapse in judgment; they exploit a systemic design flaw in how we’ve implemented a critical security control. When we train employees to expect and approve push notifications as part of their daily workflow, we are conditioning them to perform an action that attackers can hijack. The problem isn’t just that users get tired; it’s that the system allows them to be spammed into submission without any built-in safeguards, such as limiting the number of requests a user can receive in a short period. Treating this as a user error is like blaming a driver for a crash caused by a faulty traffic light.
Rethinking the Training Slide
This is why MFA fatigue needs to be front and center in every Cybersecurity Awareness Month training deck. The current official themes for 2026—like “Securing the Next 250” and “Don’t Make It Easy for Them”—are the perfect umbrellas for this conversation. But we must go beyond simply telling people to “turn on MFA.” We need to evolve. Training must explicitly teach employees to recognize the signs of an MFA bombing attack: multiple, unsolicited prompts, especially at odd hours. The message should be clear: a storm of MFA notifications is not an IT glitch; it is an active attack, and the only correct response is to deny them all and immediately report it. Companies, in turn, must move beyond basic push notifications. Adopting phishing-resistant methods like number matching—where the user has to enter a number displayed on the login screen into their app—or using biometric-based authenticators significantly raises the bar for attackers. These methods force active participation, making it impossible to approve a login out of simple fatigue.













