MFA fatigue is what happens when attackers stop trying to defeat your second factor and start trying to exhaust the human holding it. It is cheap, it scales, and it has opened doors at companies with security budgets a thousand times yours.
The good news: MFA fatigue is also one of the most fixable attack classes in the entire catalog, usually with settings you already pay for. Here is how the attack works, and the changes that shut it down.
How an MFA fatigue attack works
Step one: obtain a valid password, from a credential dump, a phishing page, or an infostealer. Step two: attempt logins on a loop, each one firing a push notification to the owner’s phone. Ten at dinner. Five more at 11 p.m. Three at 2 a.m. The target is not the cryptography; the target is annoyance.
Eventually a tired thumb taps approve to make the phone shut up, and the attacker is inside with a fully legitimate session. No malware, no exploit, no alarms. From the log’s point of view, the user simply logged in. That is what makes MFA fatigue so quietly dangerous: the breach looks exactly like a Tuesday.
When spam alone fails, attackers pair it with a nudge. A text or call pretending to be the help desk: “We are pushing a fix, just approve the prompt.” Combining annoyance with false authority is how one famous rideshare breach happened, and the technique has been photocopied ever since.
Why blind-approve prompts are the weakness
A push that asks only approve or deny carries no context and demands no thought. The fix is number matching: the login screen shows a two-digit code, and the phone requires you to type it. An attacker’s prompt shows a number you cannot see, so a sleepy approval is structurally impossible. Microsoft, Google, Okta, and Duo all support this today; in most tenants it is a checkbox you have simply not checked yet.
CISA has been banging this drum for years; its guidance on phishing-resistant MFA explicitly calls out push bombing and recommends number matching as the minimum bar. If your identity provider cannot do number matching, that fact belongs in your renewal conversation.
The settings that stop MFA fatigue
Enable number matching everywhere it exists. Add rate limiting so five denied prompts locks the account and pages someone, because a burst of denials at 2 a.m. is not noise, it is the clearest indicator of compromise you will ever get for free. Show geographic context in prompts where supported. And for admin and finance accounts, skip push entirely and issue hardware keys or passkeys, which remove the approval decision altogether.
Remember, too, that every MFA fatigue attack starts with a stolen password. Shrink that supply and you shrink the attack. A real password manager ends the reuse that feeds credential dumps, and the habit fixes we cover in your firewall isn’t the problem close the rest of the gap.
Train the one sentence
An MFA prompt you did not ask for means someone has your password. Not might mean. Means. Report it immediately and we will reset credentials with a thank-you, because that report just told us exactly which account is compromised before it cost anything.
Put that sentence in onboarding, in the security refresher, on the wall if you have to. MFA fatigue relies on users treating rogue prompts as glitches; one believed sentence converts every employee phone into a tripwire. That is the entire defense, and it costs a staff meeting.
If you want help turning the checkboxes into an actual rollout, with rate limits, conditional access, and hardware keys where they belong, that is core defend territory for us. MFA fatigue is a solved problem. It just is not a solved default, and the gap between those two is where attackers live.


