logo

How To Stop MFA Fatigue Attacks

ID: fe2c0f04-6fa8-5333-ae7d-1b57fd55344b

STIX ID: report--fe2c0f04-6fa8-5333-ae7d-1b57fd55344b

Feed Name: Arctic Wolf Blog

Threat Score
55/100

Date Published: 2024-07-15

Date Updated: 2026-04-27

...
...

This article explains MFA fatigue (also called push bombing) attacks in which an adversary who already has valid credentials repeatedly sends MFA approval prompts to a user until the user approves, enabling account takeover. It details the attack flow, references real-world incidents (e.g., Uber, 23andMe), discusses the role of credential theft, and presents practical mitigations such as limiting push notifications, switching to time-based one-time passwords or web authenticators, adding contextual checks, enhancing security training, and improving monitoring and IAM controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.