MFA Fatigue Attack (Push Bombing)

πŸ“… Published 2026-04-30 Β·attack-techniquessocial-engineeringcloud-securitythreat-analysiscase-studyawareness

Written by Aryan Giri

🧠 Overview

MFA fatigue (also known as push bombing) is a social engineering + authentication abuse technique where attackers spam multi-factor authentication (MFA) push notifications to a victim until they accidentally or knowingly approve one.

Unlike traditional exploits, this attack does not break cryptography β€” it exploits human behavior and weak MFA design assumptions.


πŸ”₯ The Core Vulnerability

What’s Broken?

Weak Design Patterns


βš™οΈ Attack Workflow (Step-by-Step)

1. Initial Access

Attacker obtains valid credentials via:

2. Authentication Abuse

3. Fatigue Phase

Victim receives dozens of prompts:

"Approve sign-in request?"

Human reactions:

4. Social Engineering Layer (Optional)

Attacker may call victim pretending to be IT support:

"We detected suspicious activity, please approve to secure your account"

5. Account Compromise


πŸ’» Practical Simulation (Lab Use Only)

Goal

Simulate repeated login attempts to trigger MFA prompts in a controlled lab environment.

Example Python Script

import requests
import time

url = "https://target-app.com/login"
data = {
    "username": "victim",
    "password": "known_password"
}

while True:
    r = requests.post(url, data=data)
    print("Triggered MFA push")
    time.sleep(2)

Tools You Can Use

⚠️ Only test on authorized labs (TryHackMe, HTB, local apps)


🧬 Why This Works (Technical Breakdown)

Trust Model Flaw

Human Factor Exploit

Lack of Context


🌍 Real-World Case Studies

1. Uber Breach (2022)

Impact:


2. Cisco MFA Fatigue Attack


3. Microsoft & Okta Targeting Campaigns


πŸ›‘οΈ Detection & Defense

Strong Mitigations

1. Number Matching (Critical)

2. Rate Limiting

3. Device Binding

4. Risk-Based Authentication

5. Passkeys / FIDO2


πŸ”„ Attacker Evolution (2025–2026 Trends)


πŸ”— References & Further Reading


🎯 Key Takeaway

MFA is not a silver bullet.

If implementation is weak:

"MFA present" β‰  "MFA secure"

Security must validate intent, not just interaction.