MFA fatigue, also called push bombing or MFA bombing, is an attack where a criminal who already has a user''s password triggers a flood of push-notification approval requests, betting the user eventually approves one out of annoyance, confusion or habit. It turns MFA''s convenience feature, one-tap approval, into the weak point.
Key facts
- It requires a valid password first (from phishing, reuse or a breach); the push flood is the second stage.
- One accidental or exasperated tap grants access, leading to account takeover.
- It exploits human behavior, not a technical flaw in MFA, which is why the fixes are both technical and procedural.
How the attack plays out
The attacker submits the login with the stolen password repeatedly, firing an approval prompt to the victim''s phone each time, sometimes at 3am, sometimes paired with a fake "IT" message urging them to approve. Eventually a prompt gets approved. High-profile breaches have started exactly this way. See also AiTM phishing for a different MFA-bypass path.
How to defend
Switch from simple push-approval to number matching (the user types a code shown on screen, so blind approval fails), or better, to phishing-resistant passkeys that have no approvable prompt to spam. Cap failed attempts and alert on push floods. And address the root: the password was stolen first, so email-layer phishing protection that stops the credential theft prevents the fatigue attack from ever starting.
How Sentaro helps
MFA fatigue is downstream of a stolen credential, and that credential is usually phished by email. Sentaro blocks the credential-phishing and AiTM lures upstream, and flags the account-takeover behavior if an approval is coerced, cutting the attack at both ends of the mailbox.