What is MFA Fatigue?

MFA Fatigue is a social engineering attack targeting multi-factor authentication processes, often referred to as Push Bombing or MFA Spamming. Attackers usually already have the target account's username and password, then repeatedly try to log in, causing the system to continually send MFA push notifications to the victim's phone or authenticator app. CISA explicitly identifies this method of overwhelming the user with verification requests until they mistakenly approve one as MFA Fatigue. What makes this attack particularly noteworthy is that attackers do not necessarily need to break MFA itself. They are truly exploiting the interaction between the user and the verification process. If a user suddenly receives numerous login requests they did not initiate and eventually presses allow due to being disturbed by the constant notifications, the attacker may successfully log in. Thus, MFA Fatigue does not imply that multi-factor authentication is ineffective; rather, it serves as a reminder to users: any MFA request that they did not initiate should not be treated as a normal notification.

Why do attackers keep sending MFA notifications?

The premise of MFA Fatigue is typically that the attacker already has some valid login information. This information may come from data breaches, phishing websites, malware, or other credential theft methods. Microsoft has publicly analyzed Push Bombing cases, noting that attackers utilize the obtained credentials to repeatedly trigger push requests, hoping that the user will mistakenly approve one of them. Attackers do not need every request to appear reasonable. On the contrary, the large number of notifications is part of their attack strategy. When users are working, sleeping, in meetings, or managing numerous phone notifications, the flood of MFA requests may gradually become a distraction, lowering the user's willingness to carefully examine each login request. The truly dangerous situation arises when users see familiar authenticator notifications and begin to regard them as ordinary system prompts rather than legitimate authentication requests.

Why might an account still be attacked even with MFA enabled?

The purpose of MFA is to add an additional factor of authentication beyond just the password, so even if the password is stolen, the attacker still needs to pass additional verification to complete the login. Microsoft also views MFA as an important security measure in reducing credential-based attacks. The problem is that different MFA methods do not offer the same level of protection. CISA points out that some push-based MFA solutions may still be susceptible to Push Bombing or MFA Fatigue if no further protective measures are implemented; therefore, they recommend gradually adopting phishing-resistant MFA, and if immediate adoption isn't possible, using Number Matching to lower the risk of push bombardment. Thus, enabling MFA does not mean that an account's security settings are entirely complete. More importantly, it is essential to understand which type of MFA you are using and what needs to be confirmed during login.

What situations warrant caution upon receiving unfamiliar MFA notifications?

The primary judgment criterion is quite simple: have you actively attempted to log in? If you are logging into Microsoft, Google, GitHub, or another service, and the authenticator suddenly prompts you to confirm a login, this is usually part of a normal process. However, if you have not attempted to log in at all and suddenly see an MFA request, you should not immediately press allow. Pay special attention to the following situations:

  • Receiving multiple login verification notifications in rapid succession.
  • Notifications showing unfamiliar login locations or devices.
  • You did not log into that service at the time.
  • Notifications asking you to quickly select allow or deny.
  • A new request appears immediately after you deny the previous one.
  • Simultaneously receiving password reset or account security warnings.

If you encounter these situations, the safest course of action is not to keep pressing deny until notifications stop, but rather to address the account itself. Microsoft's security guidelines also advise that when encountering MFA requests you did not initiate, you should first verify the request's source and, if necessary, immediately change the relevant account password.

Why can Number Matching reduce the risk of MFA Fatigue?

Traditional Push MFA has a significant issue: users may only need to press Approve or Allow to complete verification. If attackers continuously send requests, they have a chance to exploit user fatigue or errors to complete a wrongful approval. Number Matching changes this process. Once the login begins, the login page displays a set of numbers, which the user must input in the authenticator app to match what appears on the login screen, instead of simply pressing allow. CISA believes Number Matching can effectively reduce MFA Fatigue and considers it an important transitional measure when phishing-resistant MFA cannot be immediately implemented. Microsoft has also incorporated Number Matching as a critical security mechanism in Microsoft Authenticator push logins to help reduce the risk of users mistakenly approving MFA requests. However, Number Matching is not a complete solution for all MFA attacks. CISA still recommends prioritizing phishing-resistant MFA, such as FIDO/WebAuthn types of verification, when feasible.

What should you do when encountering MFA Fatigue?

If you suddenly receive a large number of MFA requests you did not initiate, the first step is to refrain from approving any requests. Even if notifications have occurred in rapid succession, do not press allow just to make them stop, as the attacker is waiting for exactly this erroneous action. Next, directly access the official account security settings of the service concerned, check recent login activity, currently logged-in devices, and authentication methods. If you suspect an attacker may know your password, immediately change to a new password not used on other services and verify that the account recovery information has not been modified. If the service supports Number Matching or stronger phishing-resistant verification methods, consider upgrading as a priority. For important accounts, utilizing Passkey or other FIDO/WebAuthn verification methods can further reduce certain attack risks faced by traditional passwords and push MFA. CISA lists FIDO/WebAuthn as widely available phishing-resistant authentication methods.

User inputs numbers displayed on the login page through the authenticator to prevent MFA Fatigue attacks

MFA Fatigue Frequently Asked Questions and How to Respond After Being Bombarded with Notifications

Receiving continuous MFA verification notifications, does it mean the attacker already knows my password?

This is a very important judgment question. MFA Fatigue typically requires the attacker to first obtain valid login credentials before continually triggering subsequent MFA verification requests. Therefore, if you suddenly receive a large number of verification notifications without any login attempt, you should consider the possibility that your password may have been obtained. Microsoft’s analysis of Push Bombing cases also points out that attackers trigger numerous MFA requests using credentials they have already obtained. However, simply receiving one unfamiliar notification does not prove that your password has necessarily been compromised. The safest approach is to directly access the account security settings via the official website or app, rather than clicking on links within the notifications, to check login activity and change your password. If the same password has been used across other services, those should also be checked.

Why is it insufficient to keep denying requests without changing my password?

Pressing deny can prevent the current MFA request, but it does not solve the problem that the attacker may already have valid account password information. If the attacker continues to have valid credentials, they can keep trying to log in and send new MFA requests. Thus, the occurrence of MFA Fatigue should be viewed as a signal regarding account security, rather than just a mobile notification issue. Changing passwords, checking login activities, verifying recovery information, and reviewing other login methods are the only ways to truly reduce the likelihood of ongoing attacks. Microsoft’s security guidelines also recommend confirming the request source for unsolicited MFA requests and, when necessary, immediately changing relevant account passwords.

Even with Number Matching enabled, should I still worry about MFA Fatigue?

Yes, but the risk will be lower. Number Matching requires users to input the numbers displayed on the login screen, making it harder for attackers to rely solely on the user mistakenly pressing Approve once to gain access. CISA views Number Matching as an effective measure to reduce MFA Fatigue, but it also clearly states that its protective capabilities still fall short of true phishing-resistant MFA. If an account supports Passkey or other FIDO/WebAuthn verification methods, especially for primary email, business accounts, or high-value accounts, it can be further beneficial to consider using these phishing-resistant methods. The intention is not because Number Matching is ineffective, but to gradually reduce reliance on login processes that are easily susceptible to social engineering.

One Key Takeaway: Do not approve unfamiliar MFA requests; first change your password, check login activity, and then upgrade to Number Matching or phishing-resistant MFA.