Understanding MFA Fatigue Attacks

MFA fatigue attacks target the human behind multi-factor authentication. After stealing a password, the attacker repeatedly tries to sign in, sending a stream of approval prompts to the victim phone. The hope is that an annoyed, tired or confused user will eventually tap approve just to make the notifications stop.
How the attack unfolds
The criminal first obtains a valid username and password through phishing, a data leak or malware. They then trigger sign-in attempts, often late at night or during busy hours, so that the push notifications arrive when the target is least alert. Some attackers follow up by contacting the victim and pretending to be IT support, saying the prompts are a glitch and asking them to approve one. A single mistaken tap gives full access.
Why basic push approval is vulnerable
A simple approve or deny button gives no context. The user cannot tell where the request came from or whether it is genuine. Because the prompt looks identical every time, approving becomes automatic. Several high-profile breaches have started exactly this way, which is why security teams now treat simple push approval as the weakest form of multi-factor sign-in.
Technical defences that work
Turn on number matching, where the user must type a number shown on the login screen into the app, so a blind approval is impossible. Limit how many prompts can be sent in a row and lock or flag the account after repeated denials. Show the location and application in the prompt. Where possible, move high-risk users such as administrators and executives to hardware security keys or passkeys, which cannot be approved remotely.
Train people to react correctly
Tell staff plainly: if you did not just try to sign in, never approve a prompt, and report it at once. Make reporting easy and blame-free, and remind them that real IT support will never ask them to approve a request they did not start. After a report, reset the password straight away, because the attacker already knows it.
Mistakes that make fatigue attacks easier
Leaving simple push approval enabled for every user is the biggest gap, followed by failing to monitor sign-in logs. A burst of failed or denied prompts is a clear warning sign, yet many organisations never alert on it. Create a rule that notifies security when a user denies several prompts or approves one from an unusual country.
Another mistake is making reporting awkward. If employees fear embarrassment or do not know whom to contact, they stay quiet. Publish a single phone number or chat channel for suspected account problems, and thank anyone who uses it, even for a false alarm. Quick reports are the best defence you have.
Frequently asked questions
Does multi-factor authentication still make sense?
Absolutely. It blocks the vast majority of account takeovers. Fatigue attacks simply show why stronger methods matter.
What should I do if I accidentally approved a prompt?
Report it immediately, change the password and ask IT to revoke active sessions.
Final thoughts
MFA fatigue attacks exploit tired humans, so combine stronger technology with clear training. Enable number matching, limit prompts, use hardware keys for important accounts and teach everyone to refuse and report unexpected requests.
Keep reading
- Threat Intelligence
Lessons From the Fake IT Worker Hired by a Security Firm

- Threat Intelligence
How Attackers Steal Browser Cookies and Bypass MFA

- Threat Intelligence
GitHub Enterprise Server Admin Bypass Fixed

- Threat Intelligence
Is Vulnerability Disclosure Broken for CISOs?
