The Annoyance Attack: Push Fatigue
One of the most common ways attackers defeat MFA is by exploiting human nature. In a technique called MFA fatigue or “push bombing,” an attacker who already has your password will trigger repeated login attempts. Each attempt sends a push notification
to your phone asking for approval. The goal is simple: to overwhelm you. After dozens of alerts, often at inconvenient times, the hope is that you’ll get so annoyed or confused that you accidentally tap “Approve” just to make it stop. High-profile breaches have proven this social engineering tactic to be startlingly effective, as it doesn't break the technology but rather targets the person using it.
The Perfect Clone: Phishing Gets Smarter
Old-school phishing emails with typos are a thing of the past. Today’s attackers use sophisticated man-in-the-middle toolkits to create pixel-perfect copies of real login pages. When you click a deceptive link, you're sent to a fraudulent site that looks and feels completely legitimate. You enter your username and password, which the attacker captures. The fake site then passes your credentials to the real service, which in turn prompts you for your MFA code. You enter the code into the fake site, the attacker grabs it, and immediately uses it to complete the login on their end, hijacking your session. Because this happens in real-time, the MFA code does its job, but for the wrong person.
The Hijacked Number: SIM Swapping
If you receive MFA codes via SMS text message, you're vulnerable to a low-tech but devastating attack called SIM swapping. This is where an attacker contacts your mobile phone provider and, using social engineering and personal information they’ve gathered about you, convinces the customer service representative to transfer your phone number to a new SIM card that they control. Once they’ve hijacked your number, any SMS-based MFA codes are sent directly to their device. From there, they can easily access your accounts, reset your passwords, and lock you out, making this one of the most direct ways to bypass a common form of MFA.
The Recovery Loopholes: Help Desk Deception
Sometimes the easiest way around a security system is to not go through it at all. Attackers can bypass MFA by targeting account recovery processes. Armed with personal data from previous breaches, an attacker might impersonate you in a call to a company’s help desk. They'll claim to have lost their phone and be unable to receive MFA prompts, asking the support agent to help them regain access to their account. If the agent can be convinced to disable MFA or reset the account using other, weaker forms of identification, the attacker gains full control without ever needing to defeat the second factor.













