How To Stop MFA Fatigue Attacks
ID: fe2c0f04-6fa8-5333-ae7d-1b57fd55344b
STIX ID: report--fe2c0f04-6fa8-5333-ae7d-1b57fd55344b
Feed Name: Arctic Wolf Blog
This article explains MFA fatigue (also called push bombing) attacks in which an adversary who already has valid credentials repeatedly sends MFA approval prompts to a user until the user approves, enabling account takeover. It details the attack flow, references real-world incidents (e.g., Uber, 23andMe), discusses the role of credential theft, and presents practical mitigations such as limiting push notifications, switching to time-based one-time passwords or web authenticators, adding contextual checks, enhancing security training, and improving monitoring and IAM controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
