What is MFA fatigue attack?

Also known as: push bombing, MFA bombing

In an MFA fatigue attack the attacker already has the victim's password and sends approval prompts to their phone over and over until the person taps "approve" out of fatigue or by mistake. It is sometimes paired with a call "from IT".

It is simple and effective because people are used to tapping approve. The defence: never approve a login you didn't start, and treat such a prompt as proof your password is already stolen.

How to spot it

  • Several approval prompts in a row
  • A call asking you to "just approve it once"

What to do

  • Deny every prompt
  • Change your password now and tell IT

Related courses

Terms on this topic

More topics

← Cybersecurity glossary

Start with your team's risk baseline

15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.