Avatier

MFA bypass

MFA fatigue

Also called: push bombing, MFA bombing

MFA fatigue is an attack that floods a user with multifactor push notifications until they approve one. The attacker already has the password and keeps triggering login prompts, often late at night or alongside a call claiming to be IT support. One tired or confused tap on approve gives the attacker a valid session.

How it works

After stealing a password, the attacker repeatedly attempts to sign in, which sends approval prompts to the user's phone. Some attackers message or call the user pretending to be the help desk and ask them to accept the prompt to make it stop. Simple approve or deny prompts, with no context, make this easier.

A real example

Citing public reporting, CISA and the FBI's Scattered Spider advisory said the group's actors had sent repeated MFA notification prompts that led employees to press the Accept button, a technique it called MFA fatigue.

Source: Scattered Spider (AA23-320A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-11-16

The Identity Attack Ledger holds 1 cited incident for mfa bypass in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.

How to stop it

Use phishing-resistant MFA, or at least number matching with sign-in context, limit how many prompts can be sent, and alert on bursts of denied pushes.

Related terms

Threat actors that use it

Sources

  1. Scattered Spider (AA23-320A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-11-16

Last reviewed Oct 2, 2026