Workforce and access social engineering · Also called push bombing, MFA bombing, push fatigue, MFA prompt spamming, MFA request generation
MFA fatigue (push bombing)
MFA fatigue, also called push bombing, is an attack in which a criminal who already has your password triggers a flood of login approval prompts on your phone. They hope you will tap Approve by accident, out of annoyance, or because a caller posing as IT tells you to, which lets them into your account.
How it works
- The criminal gets the employee's password, for example through phishing, password spraying, or an old data breach.
- They try to sign in repeatedly, so the employee's authenticator app shows push approval prompts, sometimes hundreds in a short time.
- They may call or message the employee while posing as IT, saying the prompts are expected and asking them to approve one.
- Once a prompt is approved, the criminal is signed in with the employee's access.
Red flags
- You receive many login approval prompts in a short time.
- A prompt appears when you are not trying to sign in to anything.
- Someone claiming to be from IT calls or messages and asks you to accept a prompt or read out a code.
- You get a call from IT about a password or MFA reset that you did not ask for.
If you are targeted
- Stop: deny the prompt and do not approve any request you did not start, whoever asks.
- Tell your IT security team at once, because an unexpected prompt means your password has probably been stolen.
- Change your password through the normal company process, and let security check the account for any sign-in that got through.
- Report it to your security team, then to the national service; our Report a scam page lists where, such as ic3.gov in the US.
Prevention
For individuals
- Only approve a sign-in prompt that you started yourself, seconds earlier.
- Never share a one-time code or approve a prompt because a caller asks you to.
- Use a security key or passkey where your company offers one, because it cannot be approved by accident.
For organisations
- Move to phishing-resistant MFA, such as FIDO/WebAuthn security keys or PKI-based authentication, which is not open to push bombing.
- Until then, turn on number matching for push-based MFA, so a user must type the number shown on the login screen to approve.
- Train users to report unknown or bulk prompts, and have the security team investigate every denied push request.
- Monitor for risky sign-ins, such as logins from VPN services in residential address ranges.
Real cases
2022-09 · US · Disclosed
Uber contractor account breached through repeated MFA prompts, 20222022-05 · US · Disclosed
Cisco employee targeted by vishing and MFA fatigue, 2022
Delivered through: Voice phishing (vishing)
How official datasets classify it
- MITRE ATT&CK
- T1621
Questions
- What is MFA fatigue?
- It is an attack in which someone who has your password sends repeated login approval requests to your phone until you approve one. CISA calls it push bombing and recommends phishing-resistant MFA to stop it.
- I got an MFA prompt I did not request. What should I do?
- Deny it and tell your IT security team. A prompt only appears after the password step, so an unexpected one usually means someone has your password.