← Glossary

MFA Fatigue

MFA fatigue (push bombing) floods a user with authentication prompts until they approve one. It turns MFA's one-tap convenience into the weak point.

Updated

MFA fatigue, also called push bombing or MFA bombing, is an attack where a criminal who already has a user''s password triggers a flood of push-notification approval requests, betting the user eventually approves one out of annoyance, confusion or habit. It turns MFA''s convenience feature, one-tap approval, into the weak point.

Key facts

  • It requires a valid password first (from phishing, reuse or a breach); the push flood is the second stage.
  • One accidental or exasperated tap grants access, leading to account takeover.
  • It exploits human behavior, not a technical flaw in MFA, which is why the fixes are both technical and procedural.

How the attack plays out

The attacker submits the login with the stolen password repeatedly, firing an approval prompt to the victim''s phone each time, sometimes at 3am, sometimes paired with a fake "IT" message urging them to approve. Eventually a prompt gets approved. High-profile breaches have started exactly this way. See also AiTM phishing for a different MFA-bypass path.

How to defend

Switch from simple push-approval to number matching (the user types a code shown on screen, so blind approval fails), or better, to phishing-resistant passkeys that have no approvable prompt to spam. Cap failed attempts and alert on push floods. And address the root: the password was stolen first, so email-layer phishing protection that stops the credential theft prevents the fatigue attack from ever starting.

How Sentaro helps

MFA fatigue is downstream of a stolen credential, and that credential is usually phished by email. Sentaro blocks the credential-phishing and AiTM lures upstream, and flags the account-takeover behavior if an approval is coerced, cutting the attack at both ends of the mailbox.

Questions we get asked.

What is MFA fatigue in simple terms?

An attacker with your password spams you with login-approval prompts until you tap "approve" to make them stop, handing over access.

How do attackers get the password first?

Usually phishing, credential reuse from a prior breach, or purchase from access brokers. The password is the prerequisite; the prompt flood is the exploit.

How do we stop MFA fatigue?

Use number matching or passkeys instead of one-tap push approval, rate-limit and alert on prompt floods, and stop the upstream credential theft with email security.

Is MFA still worth it given these attacks?

Yes: MFA remains essential. The lesson is to use phishing-resistant forms (passkeys, number matching) rather than simple push approval, not to drop MFA.

Stop reading about it. Watch it get blocked.

Free for one account. Four minutes to connect.