Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 325, Issue 1IT NewsMFA

Stopping MFA Fatigue Attacks Before They Start: Securing Your Entry Points

Security Boulevard, Thursday, April 3rd, 2025

Yet another challenge is undermining the effectiveness of MFA: MFA fatigue attacks. In an MFA fatigue attack (sometimes also referred to as an 'MFA bombing' or 'push bombing' attack), a hacker who already possesses a valid username and password bombards the rightful user with repeated MFA login approval requests until the user, out of confusion or frustration, finally approves one.

This low-tech social engineering tactic has proven alarmingly effective. In fact, one recent Microsoft study observed over 382,000 MFA fatigue attacks over a 12-month period. Even more worrisome, the same study found that about 1% of users will blindly accept the very first unexpected MFA prompt they receive. This number undoubtedly increases with each sequential prompt, and each of those approvals can mean an attacker silently slips past your defenses.

more →  ·  More from MFA →