MFA fatigue
Also called: push bombing, MFA bombing
MFA fatigue is an attack that floods a user with multifactor push notifications until they approve one. The attacker already has the password and keeps triggering login prompts, often late at night or alongside a call claiming to be IT support. One tired or confused tap on approve gives the attacker a valid session.
How it works
After stealing a password, the attacker repeatedly attempts to sign in, which sends approval prompts to the user's phone. Some attackers message or call the user pretending to be the help desk and ask them to accept the prompt to make it stop. Simple approve or deny prompts, with no context, make this easier.
A real example
Citing public reporting, CISA and the FBI's Scattered Spider advisory said the group's actors had sent repeated MFA notification prompts that led employees to press the Accept button, a technique it called MFA fatigue.
Source: Scattered Spider (AA23-320A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-11-16
The Identity Attack Ledger holds 1 cited incident for mfa bypass in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Use phishing-resistant MFA, or at least number matching with sign-in context, limit how many prompts can be sent, and alert on bursts of denied pushes.
Related terms
Threat actors that use it
- APT29
Profile with government sources
- Scattered Spider
Profile with government sources
Sources
- Scattered Spider (AA23-320A) — Cybersecurity and Infrastructure Security Agency (CISA), 2023-11-16
Last reviewed Oct 2, 2026