What is MFA fatigue attack?
Also known as: push bombing, MFA bombing
In an MFA fatigue attack the attacker already has the victim's password and sends approval prompts to their phone over and over until the person taps "approve" out of fatigue or by mistake. It is sometimes paired with a call "from IT".
It is simple and effective because people are used to tapping approve. The defence: never approve a login you didn't start, and treat such a prompt as proof your password is already stolen.
How to spot it
- Several approval prompts in a row
- A call asking you to "just approve it once"
What to do
- Deny every prompt
- Change your password now and tell IT
Related courses
Terms on this topic
More topics
Start with your team's risk baseline
15-30 employees, one phishing simulation and a one-page report for management. No annual commitment.