MFA fatigue
A barrage of approval notifications until the victim accepts out of exhaustion. The attacker already has the password; only the second factor is missing.
Full definition
MFA fatigue is an attack where the adversary, who already has the victim's password, fires bursts of login approval requests until the person accepts one: out of exhaustion, confusion, or just to silence the phone. It is also known as MFA bombing or MFA push spam.
The attack exploits a design meant for convenience: one-tap approval. At dawn, in the middle of a meeting, or after the twentieth notification, accepting looks like the fastest way out. It is sometimes reinforced by a fake tech support call asking the victim to approve the request to fix a supposed problem.
Mitigations are concrete: number matching that forces typing a code shown on screen, request rate limits, phishing-resistant factors such as hardware keys, and training the correct response, which is to reject and report, not to accept so it stops.
Related terms
Multi-factor authentication (MFA)
Identity verification with two or more independent factors. It makes a stolen password insufficient, though not invulnerable.
Vishing
Social engineering over a phone call. The attacker poses as tech support, a bank or a vendor to obtain access or payments in real time.
Account takeover (ATO)
Taking control of a legitimate account with stolen credentials. From inside, the attacker reads, impersonates and escalates without raising alarms.
From definition to data: measure your company's human risk
Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.