Understanding MFA Fatigue: Why Cybercriminals Are Exploiting Human Behaviour
IT Security Guru, Tuesday, February 25th, 2025
The common maxim in cybersecurity is that the industry is always on the back foot. While cybersecurity practitioners build higher walls, adversaries are busy creating taller ladders. It's the nature of the beast.
A prime example is multi-factor authentication (MFA), a security process that requires users to verify their identity in two or more ways, such as a password, a code sent to their phone, or a fingerprint. Many are adopting these tools to protect their digital assets, but malefactors are honing their strategies to undermine this critical layer of security.
Unfortunately for the industry, to err is human, and people are susceptible to all sorts of manipulation of their natural biases and behaviours. This has seen MFA fatigue emerge as a dangerous threat, because this type of attack exploits a basic yet powerful vulnerability: human behaviour.