Knowledge / identity detection

MFA fatigue

Bombard the user's phone with push prompts until they tap Allow. MFA still on. Judgement off.

MFA fatigue, or push bombing, is a social-engineering pattern against prompt-based multi-factor authentication: many push notifications until the user accepts one, or accepts to make it stop. The password was already stolen or sprayed. The second factor became a nuisance to dismiss.

Number matching, phishing-resistant factors such as FIDO2 and hardware tokens, and alerts on MFA failure bursts cut this. SMS and open-ended push are weaker against it. MFA is still required; tired MFA is not a strategy.

See also: Multi-factor authentication, Phishing, Identity and access management, Authentication.