Back to the glossary
    Credentials & identityCybersecurity glossary

    MFA fatigue

    A barrage of approval notifications until the victim accepts out of exhaustion. The attacker already has the password; only the second factor is missing.

    Full definition

    MFA fatigue is an attack where the adversary, who already has the victim's password, fires bursts of login approval requests until the person accepts one: out of exhaustion, confusion, or just to silence the phone. It is also known as MFA bombing or MFA push spam.

    The attack exploits a design meant for convenience: one-tap approval. At dawn, in the middle of a meeting, or after the twentieth notification, accepting looks like the fastest way out. It is sometimes reinforced by a fake tech support call asking the victim to approve the request to fix a supposed problem.

    Mitigations are concrete: number matching that forces typing a code shown on screen, request rate limits, phishing-resistant factors such as hardware keys, and training the correct response, which is to reject and report, not to accept so it stops.

    Related reading on the blogGo deeper into this topic

    Related terms

    From definition to data: measure your company's human risk

    Fensivo detects leaked credentials, simulates real attacks and validates with retests that behavior changed.