Meet MFA Fatigue: Security as Annoyance
First, let's get on the same page. Multi-factor authentication (MFA) is your digital life's double-lock system. Even if a thief steals your password (the first key), they still need a second factor—usually your phone—to get in. The most common method
is a push notification sent to an authenticator app. You get a pop-up, tap "Approve," and you're in. Simple and effective. But hackers have figured out how to turn this convenience against you. An MFA fatigue attack, also called "push bombing," is brutally simple. After a hacker gets your password (often from a previous data breach), they try to log in as you. You get a push notification. You deny it. They try again. You deny it. They try again, and again, and again—sometimes hundreds of times, often in the middle of the night. The goal is to annoy, confuse, and exhaust you until you finally hit "Approve" just to make the alerts stop.
The Dangerous Detail: The 'Approve' Button Itself
Here’s the detail the headline promises: the danger lies in the simplicity of the standard "Approve/Deny" prompt. For years, the default design for many authenticator apps was a simple, binary choice that required no real thought. You could approve a login from your lock screen without even opening the app. This low-friction design is a feature, not a bug—it’s meant to make security seamless. But it creates a critical vulnerability. When you're being spammed with requests, that effortless "Approve" button becomes a tripwire. Each notification looks legitimate because the attacker is using your real password. There's no context, just a generic request. Is this login attempt from your office or from a server on another continent? The basic push alert doesn't tell you. Hackers are exploiting the gap between the notification's arrival and the user's awareness. They are betting on a moment of distraction, frustration, or confusion for you to make that single, catastrophic tap.
How It Plays Out in the Real World
This isn't a theoretical threat. It’s how major companies get breached. In 2022, Uber suffered a significant security incident thanks to this exact technique. An attacker, believed to be part of the Lapsus$ hacking group, bought an employee's password on the dark web. They then bombarded the employee with MFA push notifications for over an hour. The attacker even contacted the employee on WhatsApp, pretending to be from Uber's IT department and telling them to accept the prompt. Eventually, the employee gave in. That one tap gave the hackers initial access, which they used to pivot deeper into Uber's internal systems. Cisco experienced a similar breach, where an attacker used a combination of MFA fatigue and voice phishing to trick an employee into accepting a fraudulent login. These attacks prove that even with MFA in place, targeting the human element remains a highly effective strategy for determined criminals.
The Solution: Making Approvals Intentional
The good news is that the security industry is adapting. The defense against MFA fatigue is to make the approval process more deliberate. The most effective countermeasure is called "number matching." Instead of a simple "Approve/Deny" button, the login screen shows you a two-digit number. To approve the sign-in, you must type that same number into the authenticator app on your phone. This small step is a game-changer. It forces the user to actively engage with both the device they're logging into and the phone they're using to approve it, proving they are present for that specific login. It makes accidentally approving a fraudulent request nearly impossible. Recognizing the risk, major providers like Microsoft have begun making number matching the default setting. Other key defenses include limiting the rate of login attempts and providing more context with the notification, such as the geographic location of the login attempt, so a user can easily spot an anomaly.













