MFA Fatigue Attacks: When Hackers Spam You With Login Requests

by Daniil Slesarenko

When MFA Becomes the Target

Multi-factor authentication (MFA) is one of the most effective ways to protect an account, but it is not impossible to bypass. Cybercriminals have found a simple weakness they can exploit: the person receiving the MFA request.

MFA fatigue attacks, sometimes called MFA bombing, involve repeatedly sending login approval requests to a user until they eventually accept one. The attacker may already have the victim's username and password and is simply trying to convince them to approve the final step.

 

How MFA Fatigue Attacks Work

The attack usually begins with the attacker obtaining a user's password. This could come from a previous data breach, phishing attack, password reuse, or stolen credentials.

The attacker then attempts to log in to the victim's account. Because MFA is enabled, the login cannot be completed without approval from the user.

Instead of giving up, the attacker sends another request. Then another. The notifications might arrive through an authenticator app, text message, phone call, or another MFA method.

Eventually, the constant notifications can become frustrating or confusing. The user may accidentally approve the request simply to make the notifications stop.

Once approved, the attacker may gain access to the account.

 

Why These Attacks Work

MFA fatigue attacks take advantage of human behavior rather than a technical vulnerability in MFA itself.

Someone who receives several login requests may assume there is a problem with their device, believe they accidentally triggered the requests, or simply click "Approve" without thinking carefully.

Attackers can also make the situation more convincing. They may contact the victim by phone or email and pretend to be an IT employee investigating a login problem. This gives the victim a reason to expect an MFA notification.

The attacker is essentially trying to turn security notifications into background noise.

 

What Can Happen After an MFA Approval

An unauthorized MFA approval can give an attacker access to much more than a single application.

Depending on the compromised account, the attacker could access email, company documents, cloud services, internal systems, or other applications connected to the account.

A compromised employee account can also become a starting point for further attacks. The attacker may use the account to impersonate the employee, send phishing messages to coworkers, access sensitive information, or attempt to compromise additional accounts.

 

How to Protect Against MFA Fatigue

Users should never approve an MFA request they did not initiate. If unexpected requests continue appearing, the safest response is to stop interacting with them and report the activity to IT or the security team.

Organizations can also reduce the effectiveness of MFA fatigue attacks by using stronger authentication methods. Number matching, where the user must enter a number displayed on the login screen, makes accidental approvals more difficult. Hardware security keys and phishing-resistant authentication methods provide even stronger protection.

Security teams should also monitor repeated failed authentication attempts and unusual MFA activity. A sudden series of authentication requests can be an important warning sign that someone's credentials may already have been compromised.

 

Don't Approve What You Didn't Request

MFA is still an important security control, but it works best when users understand what they are being asked to approve.

If an MFA notification appears unexpectedly, don't assume it is harmless. It may mean someone already knows your password and is trying to get you to open the final door for them.

If you didn't try to log in, don't approve the request. Report it.

Next
Next

Moving to Proxmox: Why It Matters and How We Do It