Skip to main content
New: free AI Readiness Assessment, see where your business stands
bdManagedIT
All articles

Cybersecurity

MFA Fatigue Attacks: How Push Bombing Works and How to Stop It

An MFA fatigue attack floods a user with sign-in approval prompts until the person approves one by mistake, out of frustration, or because an attacker poses as support.

By Wil Gibson July 28, 2026 8 min read
MFA Fatigue Attacks: How Push Bombing Works and How to Stop It

An MFA fatigue attack floods a user with sign-in approval prompts until the person approves one by mistake, out of frustration, or because an attacker poses as support. It is also called push bombing, MFA bombing, or push fatigue. The attacker normally has the password already; the repeated prompt is an attempt to defeat the second factor.

A denied prompt is not an inconvenience to ignore. It is evidence that someone may be trying to use the account. The safest employee response is to deny the request, stop interacting with unexpected prompts, and contact IT through a known channel.

How does an MFA fatigue attack work?

The attack usually begins with a stolen or guessed password. The criminal attempts to sign in, which generates a push notification on the real user’s phone. If the user denies it, the attacker tries again and again. Some attackers then call or message the employee while pretending to be the help desk and tell them to approve the next request.

CISA describes MFA fatigue or push bombing as repeated mobile push notifications intended to make the user approve through accident or annoyance. That means the prompt itself is part of the incident, even when access has not yet been approved.

What are the warning signs of push bombing?

  • A sign-in approval appears when you are not actively signing in.
  • Several prompts arrive within seconds or continue over a longer period.
  • A caller or message claims to be IT and asks you to approve a prompt, read out a code, or change an authentication method.
  • The prompt shows an unfamiliar location, application, or number.
  • A password reset, account-recovery message, or security notification appears at the same time.

What should an employee do when an unexpected MFA prompt appears?

Deny the request and report it immediately. Do not approve it just to stop the notifications, and never approve a request because someone calls and claims to be support. Use the company’s known help-desk number or reporting channel rather than replying to the message that accompanied the prompt.

If the password may have been entered on a phishing site, change it from a known-clean device. IT should review the account’s sign-in logs, revoke active sessions, confirm the registered MFA methods, check for mailbox forwarding or application consent changes, and determine whether other accounts received similar prompts.

Does number matching stop MFA fatigue?

Number matching makes accidental approval harder by requiring the user to enter the number shown on the sign-in screen. Microsoft documents number matching for Authenticator push notifications as a security improvement over a simple Approve or Deny prompt.

It is an important control, but it is not permission to approve an unexpected request. An attacker who is actively speaking to the victim may still try to obtain the displayed number through social engineering. Employees must understand that support should not ask them to approve an unsolicited sign-in.

What is phishing-resistant MFA?

Phishing-resistant MFA uses authentication bound to the legitimate service, such as FIDO2 security keys, passkeys, Windows Hello for Business, or certificate-based methods in appropriate environments. Microsoft’s phishing-resistant MFA guidance explains why traditional push and one-time-code methods remain vulnerable to modern social engineering and interception.

Start with administrators, finance, executives, remote-access users, and anyone with broad access to customer or regulated data. A phased rollout is usually more practical than trying to replace every authentication method at once.

How can a small business reduce MFA fatigue risk?

  1. Require MFA for every remote and cloud account, especially administrator access.
  2. Enable number matching and show application or location context where supported.
  3. Move privileged and high-risk users to phishing-resistant methods.
  4. Block legacy authentication and use conditional-access policies appropriate to the business.
  5. Alert on repeated denied prompts, impossible travel, unfamiliar locations, and changes to authentication methods.
  6. Train employees to deny and report unexpected prompts without fear of blame.

bdManagedIT helps North Georgia businesses configure multi-factor authentication as part of a managed identity and security program. If you are unsure which controls are already in place, start with the cyber security self-assessment and use the result to prioritize identity gaps.

Frequently asked questions

What is an MFA fatigue attack?
An MFA fatigue attack repeatedly sends sign-in approval prompts to a real user after an attacker has obtained or guessed the password. The goal is to make the user approve through accident, annoyance, or social engineering.
What is push bombing?
Push bombing is another name for MFA fatigue or MFA bombing. It describes repeated mobile authentication prompts used to pressure a person into approving an attacker’s login.
Should I change my password after an unexpected MFA prompt?
Report the prompt immediately. If you entered the password on a suspicious site, reused it elsewhere, or IT confirms a malicious sign-in attempt, change it from a known-clean device and revoke existing sessions.
Is number matching enough to stop push bombing?
Number matching greatly reduces accidental approvals, but an attacker may still try to obtain the number through social engineering. It should be paired with employee training, monitoring, conditional access, and phishing-resistant MFA for high-risk accounts.
Which MFA methods are phishing-resistant?
Common phishing-resistant options include FIDO2 security keys, passkeys, Windows Hello for Business, and certificate-based authentication where appropriate. Availability depends on the identity platform and application.

Want a straight answer for your business?

Book a first appointment with a bdManagedIT strategist. No sales script, no obligation.

Book your first appointment