The playbookpush bombing · MFA bombing · push fatigue

MFA fatigue

Repeatedly triggering push approval prompts against an account whose password the attacker already holds, until the owner approves one to make the phone stop. Often paired with a call claiming to be IT and asking them to accept.

Why it matters to you

This is a design consequence, not a user failure. A factor that can be satisfied by a single tap has no way to express "I did not start this", so blaming the person who tapped fixes nothing. Number matching, or a factor bound to the login itself, removes the option. The signature in the logs is a run of denials inside a few minutes followed by one approval, and the denials are the incident rather than its footnote.

Where we meet it

It is discussed as an add on rather than as an attack: something you do after buying credentials, often alongside a calling service that supplies the voice on the phone. The technique costs almost nothing next to the access it converts.