24/7 INCIDENT RESPONSE
(877) 259-0509
← Topics

CYBER CENTAURS TOPIC

What Is MFA Fatigue?

Cloud & Identity Investigations

MFA fatigue is a social-engineering pattern where attackers generate repeated authentication prompts until a user approves one.

MFA fatigue is a social-engineering attack pattern in which an attacker triggers repeated multifactor authentication prompts until a user approves one, often out of confusion, annoyance, or mistaken belief that the request is legitimate. It is also called push fatigue, MFA bombing, or push notification abuse.

How MFA Fatigue Works

The attacker usually has a valid username and password, or another way to initiate authentication. They attempt to sign in and repeatedly trigger push notifications. The user may eventually tap approve, especially if the prompt arrives during a busy workday, after-hours support interaction, or a fake help-desk call. Once approved, the attacker may receive a valid session and begin cloud or mailbox activity.

MFA fatigue can lead to session hijacking or business email compromise if the account provides mailbox, file, finance, or administrative access. The resulting activity may include inbox rules, data downloads, OAuth consent, external sharing, or fraudulent communications.

Evidence Investigators Review

  • Authentication attempts, failed attempts, MFA challenge results, and sign-in risk details.
  • User reports of repeated prompts, help-desk contact, or suspicious calls/messages.
  • Successful sign-ins from unfamiliar IP addresses, devices, or locations shortly after prompt activity.
  • Mailbox, SharePoint, OneDrive, Teams, or administrative events following the successful prompt.
  • Changes to MFA methods, registered devices, recovery information, or conditional access outcomes.

Modern Mitigations

Number matching can reduce accidental approval because the user must enter or confirm a value shown on the sign-in screen. Conditional access can limit where and how authentication succeeds. Phishing-resistant authentication, such as FIDO2 security keys or certificate-based authentication where appropriate, can further reduce susceptibility to prompt abuse and credential phishing.

No single control eliminates identity compromise. Controls need to be combined with monitoring, user reporting paths, session revocation, app-consent review, device compliance, least privilege, and prompt investigation of unusual MFA patterns.

Why It Matters

In Data Breach & Incident Response, MFA fatigue is important because a successful prompt may appear as a legitimate user approval unless reviewed in context. A careful investigation distinguishes the authentication event from downstream actions and assesses whether the attacker accessed data, changed mailbox settings, or established persistence.

References

NEED ASSISTANCE?

Discuss the Matter
With Cyber Centaurs.

If this topic relates to an active incident, forensic matter, or security concern affecting your organization, contact Cyber Centaurs to discuss the circumstances directly.

CONTACT CYBER CENTAURS →