Sentinel Vault
← All field notes
Device & Personal Security · November 15, 2025

How Criminals Exploit MFA Fatigue Attacks - and How to Stop Them

Multi-factor authentication (MFA) remains one of the strongest defenses organizations can use to protect accounts. But as MFA becomes standard, attackers have adapted. One of the fastest-growing techniques now targeting businesses is the MFA fatigue attack, a social engineering method that overwhelms users with endless push notifications until they accidentally (or intentionally) approve one.

It’s simple, effective, and frequently successful.


What Is an MFA Fatigue Attack?

In an MFA fatigue attack, criminals gain a victim’s username and password, usually through phishing, credential stuffing, or buying stolen credentials on the dark web. Once they have the login, they attempt to sign in repeatedly, triggering push-based MFA prompts on the victim’s phone.

The victim begins receiving:

  • Dozens of login approval prompts
  • Text messages with MFA codes they didn’t request
  • Repeated push notifications, often late at night

The attacker’s goal is to wear the victim down until they click “Approve” just to make the notifications stop.

And it works more often than most people realize.


Why These Attacks Work

MFA fatigue attacks exploit human behavior, not technology. Attackers succeed because:

1. Users assume it’s a glitch

Many employees don’t recognize the alerts as an attack. They think an app is malfunctioning.

2. Stress + fatigue = bad decisions

Late-night prompts or rapid-fire notifications push users into “just approve it” mode.

3. Push notifications are too easy to accept

All it takes is one tap to let the attacker in.

4. Criminals escalate their manipulation

If push spam doesn’t work, attackers often message the victim pretending to be IT:

“Sorry about the MFA spam. To stop it, please approve the last request.”

Victims fall for this social engineering far more than organizations expect.


What Happens Once the Attacker Gets In

A single approved login is enough to trigger a chain of compromise:

  • Email account takeover
  • Access to internal systems
  • Password resets
  • Business email compromise (BEC)
  • Payroll or vendor fraud
  • Cloud environment infiltration
  • Sensitive document exfiltration

In many incidents, attackers quietly set up their own MFA or forwarding rules so they can re-enter the account later, undetected.


How to Protect Your Organization

MFA fatigue attacks can be stopped — but it requires strategic changes.

1. Move to number-matching MFA

Push notifications should require entering a code displayed on the login screen, not a simple Approve/Deny button.
Microsoft, Duo, and Okta all support this.

2. Add impossible travel alerts

If a login attempt comes from another country minutes after a domestic login, block it automatically.

3. Lock accounts after too many prompts

Rate-limit MFA attempts so attackers can’t spam endlessly.

4. Enforce strong password policies

Compromised passwords are the root cause. Require:

  • Length over complexity
  • Password managers
  • No password reuse across accounts

5. Train users to report MFA bombs immediately

Any unrequested MFA prompt = treat it as an active attack.

6. Enable Conditional Access or Zero Trust controls

Block MFA prompts entirely if the device or location is suspicious.


Bottom Line

MFA is still essential, but push-based MFA by itself is no longer enough. As criminals shift tactics, organizations must evolve their defenses. The combination of number-matching MFA, behavioral detection, and user awareness can stop MFA fatigue attacks before they lead to business email compromise, financial loss, or system takeover.

If your organization needs help evaluating your MFA setup or implementing stronger access controls, Sentinel Vault can provide a clear, prioritized action plan without scare tactics or vendor pressure.

Want deeper insight into national cybercrime trends?

Review the FBI’s official IC3 Annual Report for real-world statistics and victim loss data:
🔗 https://www.ic3.gov/annualreport/reports

Frequently asked
What is an MFA fatigue attack?
It is a social-engineering technique where a criminal who already has your username and password, usually from phishing, credential stuffing, or stolen credentials, signs in repeatedly to trigger a flood of push notifications on your phone. The goal is to wear you down until you tap Approve just to make the prompts stop, and attackers often time the spam for late at night.
Why do MFA fatigue attacks work so often?
They exploit human behavior, not technology. Many users assume the repeated prompts are an app glitch, stress and fatigue push people into just-approve-it mode, and a push notification takes only one tap to accept. Attackers also escalate by posing as IT, saying sorry about the MFA spam and asking you to approve the last request to stop it, and victims fall for that more than organizations expect.
What happens once an attacker gets one approval?
A single approved login can trigger a chain of compromise: email account takeover, access to internal systems, password resets, business email compromise, payroll or vendor fraud, cloud infiltration, and document theft. Attackers frequently set up their own MFA or mail-forwarding rules so they can quietly re-enter the account later, undetected.
How do you stop MFA fatigue attacks?
Move from a simple approve or deny push to number-matching MFA, where the user must type a code shown on the login screen; Microsoft, Duo, and Okta all support it. Add impossible-travel alerts for logins from unexpected locations, limit how many prompts can be sent in a short window, and train employees never to approve a prompt they did not personally start.
About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.