logo

How To Stop MFA Fatigue Attacks

ID: 95510058-6972-52d7-9c29-313bf986ea03

STIX ID: report--95510058-6972-52d7-9c29-313bf986ea03

Feed Name: Arctic Wolf

Threat Score
50/100

Date Published: 2024-07-15

Date Updated: 2026-07-25

Author: Arctic Wolf

...
...

This report describes MFA fatigue (also called push bombing) attacks — where attackers with stolen credentials repeatedly trigger MFA push notifications to coerce users into approving access — outlines the attack stages and real-world examples (e.g., Uber, 23andMe), explains how credential theft enables these attacks, and lists practical mitigations including limiting push attempts, using web authenticators or TOTP, adding contextual checks, improving security awareness training, and deploying identity-aware monitoring and IAM controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.