Scott Smith

Founder and CEO of TerraKodeSeptember 12, 20265 min read

MFA Fatigue Attacks Explained: The 2 AM Push That Opens Your Front Door

An MFA fatigue attack floods your phone with push requests until you tap approve. Here's how it works, why it succeeds, and the one setting that stops it.

MFA Fatigue Attacks Explained: The 2 AM Push That Opens Your Front Door

MFA Fatigue Attacks Explained: The 2 a.m. Push That Opens Your Front Door

It's 2:14 a.m. Your phone buzzes:Approve sign-in?You tap Deny. It buzzes again. Then again. By the fortieth request, you make a tired, impulsive choice: tap Approve and make it stop. You've just handed an attacker access to your business email - and everything it can reset: payroll, cloud storage, and banking portals.

TL;DR:MFA fatigue attacks use repeated push notifications to trick users into approving access while they're distracted or worn down. Number matching MFA blocks this tactic because an attacker cannot approve a prompt without the number shown on the login screen. Your IT provider can usually enable it in minutes.

Key Takeaways:

  • MFA fatigue attacks hit users with repeated push notifications, often at inconvenient times. One wrong tap can let an attacker access your account.
  • Number matching MFA requires you to type a number shown on the login screen. It blocks blind approvals and usually takes an IT provider about five minutes to enable.
  • Phishing-resistant MFA, such as hardware keys or passkeys (FIDO2), offers stronger protection. These methods refuse to authenticate on fake sites, so a stolen password and a tired user aren't enough.
  • Set tripwires to detect MFA fatigue early. Lock accounts after repeated denials or flag logins outside normal hours. Give your team one rule:"A push you didn't trigger is an attack - deny it and report it."
  • Microsoft logged over 382,000 MFA fatigue attacks in one year. That is more than 382,000 chances for attackers to catch a user at the wrong moment.
  • Enabling number matching MFA takes about five minutes for an IT provider. It blocks the repeated-prompt tactic and reduces the risk of a breach driven by fatigue.

Microsoft logged over 382,000 MFA fatigue attacks in a single year.The fix is often one setting. Turn on number matching before the next late-night alert.

What an MFA Fatigue Attack Actually Is

Here's how it works: A criminal already has your password - stolen, bought, or reused. They test it through credential stuffing, an automated login attempt against many accounts. Once your MFA sends a push notification, they keep trying. Dozens of prompts arrive, often at night, with messages like"We're running a security test - just approve the next prompt."

This is also called push bombing or MFA prompt bombing. The goal is simple: wear down your patience until you approve the request. One sleepy tap can let an attacker reset your payroll, cloud storage, and banking portals - all through your business email.

Why It Works

Why It Works - MFA fatigue attack
Photo by McElspeth on Pixabay
  • Push-based MFA:Turns a security decision into one tap.
  • Approve and Deny:Sit side by side on the same screen.
  • Attackers:Need just one mistake - and they get it without cost.

Business email:Is the key to everything.Security decision:Becomes a battle of endurance you can't win unless you change the interface.

⚠️Warning:You won't even notice until it's too late.

The Fix: Make the Push Prove You Have the Login Screen

  • Number Matching:Enable number matching - it's the first line of defense. The login screen shows a two-digit number, and your phone asks you to type it. This proves you're viewing the real login page.
  • Phishing-Resistant MFA:Use hardware security keys or passkeys (FIDO2) for critical accounts. These methods add a layer attackers can't bypass - no code to type, no prompt to bomb.
  • Tripwires:Set rules to catch attacks early. Lock accounts after repeated denials. Alert on logins outside normal hours or impossible travel.

Microsoft Data:Number matching blocks a measurable share of these attacks. It's available in Microsoft 365 and most major MFA apps, often as a single admin toggle.

💡Tip:Give your team one rule: "A push you didn't trigger is an attack - deny it and report it."

⚠️Warning:If a bombardment starts, change the underlying password immediately. The pushes mean someone already has it.

Conclusion

AnMFA fatigue attackturns yoursecond factorinto a snooze button. Don't play along.Turn on number matchingtoday.

  • Never approve a promptyou didn't trigger.
  • Teach your teamthe same two rules.
  • Open your MFA admin settingsnow - the fix is often onecheckbox.

⚠️Warning:Tonight's2 a.m. bombardmentwill hit a wall if you don't act.

Sources

  1. Consumer Financial Protection Bureau Data
  2. Cybersecurity and Infrastructure Security Agency Resources
  3. NIST Cybersecurity Framework

Frequently Asked Questions

Q: How does an MFA fatigue attack trick users into approving a login request?

A: An attacker first obtains your password through theft or credential stuffing, then sends dozens of push notifications to your device, often late at night. The repeated prompts overwhelm you, causing fatigue and leading to an accidental approval. This single mistake gives the attacker access to your account and any linked services.

Q: What is number matching MFA and why is it effective against fatigue attacks?

A: Number matching MFA displays a random two‑digit code on the login screen and requires you to type that exact code on your authentication device. Because the code changes with each login, an attacker cannot approve a prompt without seeing the real login page, effectively blocking blind approvals and fatigue‑based exploitation.

Q: Can phishing‑resistant MFA methods like hardware keys prevent MFA fatigue attacks?

A: Yes. Hardware security keys and passkeys (FIDO2) only authenticate against legitimate websites, refusing to respond to fake login pages. Even if an attacker bombards you with push notifications, these methods will not approve the request unless you physically confirm on the key or device, making fatigue attacks ineffective.

Q: What steps can organizations take to detect and stop MFA fatigue attacks early?

A: Set up tripwires such as locking accounts after multiple denied pushes, flagging logins outside normal hours, and monitoring for impossible travel patterns. Establish a clear rule: any push you didn’t trigger is an attack, deny it and report it immediately. Enabling number matching MFA and using phishing‑resistant methods further reduces the risk.

Q: How quickly can an IT provider enable number matching MFA to protect against fatigue attacks?

A: Enabling number matching MFA usually takes about five minutes for an IT provider. It’s a simple admin toggle in most MFA platforms, including Microsoft 365, and instantly blocks the repeated‑prompt tactic that drives fatigue attacks.

About the Author

Scott Smith is the founder and CEO of TerraKode. He builds SaaS for the markets everyone else ignores: document collection, security, and workflow tools for small firms. He writes the guides he wished existed when he was on the other side of the table.

Tired of chasing documents?

DocChaser organizes document requests, reminders, secure uploads, and tracking in one branded workflow for mortgage professionals.

See DocChaser