Stopping MFA Fatigue Attacks Before They Start: Securing Your Entry Points
Security Boulevard, Thursday, April 3rd, 2025
Yet another challenge is undermining the effectiveness of MFA: MFA fatigue attacks. In an MFA fatigue attack (sometimes also referred to as an 'MFA bombing' or 'push bombing' attack), a hacker who already possesses a valid username and password bombards the rightful user with repeated MFA login approval requests until the user, out of confusion or frustration, finally approves one.
This low-tech social engineering tactic has proven alarmingly effective. In fact, one recent Microsoft study observed over 382,000 MFA fatigue attacks over a 12-month period. Even more worrisome, the same study found that about 1% of users will blindly accept the very first unexpected MFA prompt they receive. This number undoubtedly increases with each sequential prompt, and each of those approvals can mean an attacker silently slips past your defenses.