[{"data":1,"prerenderedAt":52},["ShallowReactive",2],{"glossary:mfa-fatigue":3},{"term":4,"published":46,"modified":46,"mentions":47,"related":51},{"slug":5,"title":6,"lede":7,"blocks":8,"faqs":33},"mfa-fatigue","MFA Fatigue","MFA fatigue (push bombing) floods a user with authentication prompts until they approve one. It turns MFA's one-tap convenience into the weak point.",[9,12,15,21,23,25,27,29,31],{"t":10,"text":11},"p","MFA fatigue, also called push bombing or MFA bombing, is an attack where a criminal who already has a user''s password triggers a flood of push-notification approval requests, betting the user eventually approves one out of annoyance, confusion or habit. It turns MFA''s convenience feature, one-tap approval, into the weak point.",{"t":13,"text":14},"h2","Key facts",{"t":16,"items":17},"ul",[18,19,20],"It requires a valid password first (from phishing, reuse or a breach); the push flood is the second stage.","One accidental or exasperated tap grants access, leading to account takeover.","It exploits human behavior, not a technical flaw in MFA, which is why the fixes are both technical and procedural.",{"t":13,"text":22},"How the attack plays out",{"t":10,"text":24},"The attacker submits the login with the stolen password repeatedly, firing an approval prompt to the victim''s phone each time, sometimes at 3am, sometimes paired with a fake \"IT\" message urging them to approve. Eventually a prompt gets approved. High-profile breaches have started exactly this way. See also AiTM phishing for a different MFA-bypass path.",{"t":13,"text":26},"How to defend",{"t":10,"text":28},"Switch from simple push-approval to number matching (the user types a code shown on screen, so blind approval fails), or better, to phishing-resistant passkeys that have no approvable prompt to spam. Cap failed attempts and alert on push floods. And address the root: the password was stolen first, so email-layer phishing protection that stops the credential theft prevents the fatigue attack from ever starting.",{"t":13,"text":30},"How Sentaro helps",{"t":10,"text":32},"MFA fatigue is downstream of a stolen credential, and that credential is usually phished by email. Sentaro blocks the credential-phishing and AiTM lures upstream, and flags the account-takeover behavior if an approval is coerced, cutting the attack at both ends of the mailbox.",[34,37,40,43],{"q":35,"a":36},"What is MFA fatigue in simple terms?","An attacker with your password spams you with login-approval prompts until you tap \"approve\" to make them stop, handing over access.",{"q":38,"a":39},"How do attackers get the password first?","Usually phishing, credential reuse from a prior breach, or purchase from access brokers. The password is the prerequisite; the prompt flood is the exploit.",{"q":41,"a":42},"How do we stop MFA fatigue?","Use number matching or passkeys instead of one-tap push approval, rate-limit and alert on prompt floods, and stop the upstream credential theft with email security.",{"q":44,"a":45},"Is MFA still worth it given these attacks?","Yes: MFA remains essential. The lesson is to use phishing-resistant forms (passkeys, number matching) rather than simple push approval, not to drop MFA.","2026-09-08",[48,49,50],"account-takeover","aitm-phishing","phishing",[49,48,50],1789658069607]