Skip to content

Workforce and access social engineering · Also called push bombing, MFA bombing, push fatigue, MFA prompt spamming, MFA request generation

MFA fatigue (push bombing)

MFA fatigue, also called push bombing, is an attack in which a criminal who already has your password triggers a flood of login approval prompts on your phone. They hope you will tap Approve by accident, out of annoyance, or because a caller posing as IT tells you to, which lets them into your account.

How it works

  1. The criminal gets the employee's password, for example through phishing, password spraying, or an old data breach.
  2. They try to sign in repeatedly, so the employee's authenticator app shows push approval prompts, sometimes hundreds in a short time.
  3. They may call or message the employee while posing as IT, saying the prompts are expected and asking them to approve one.
  4. Once a prompt is approved, the criminal is signed in with the employee's access.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

Real cases

Delivered through: Voice phishing (vishing)

How official datasets classify it

MITRE ATT&CK
T1621

Questions

What is MFA fatigue?
It is an attack in which someone who has your password sends repeated login approval requests to your phone until you approve one. CISA calls it push bombing and recommends phishing-resistant MFA to stop it.
I got an MFA prompt I did not request. What should I do?
Deny it and tell your IT security team. A prompt only appears after the password step, so an unexpected one usually means someone has your password.

Related scams

Read more