• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

MFA Fatigue Attack

Also known as: Push Bombing, Push Harassment, MFA Prompt Bombing, Push Fatigue, Push Phishing

COMPROMISE

Attacker who already possesses stolen credentials repeatedly triggers MFA push notifications to the victim's device -- sometimes hundreds in succession -- until the victim approves one out of frustration, confusion, or accidental tap. Often combined with social-engineering calls where the attacker p…

Defense

How to defend against this

How to spot it

  • Receiving rapid-fire MFA push notifications you did not initiate
  • Unexpected phone call from IT support asking you to approve an MFA prompt
  • MFA prompts arriving at unusual hours or from unfamiliar geographic locations
  • Seeing a login attempt notification for a service you are not currently accessing

Tools you can use

  • Hardware Security KeysCost medium · Effect high

Further reading

  • BeyondTrust

    Definition, attack flow, and defense strategies for MFA fatigue attacks including Uber/Lapsus$ case study

  • Cisco Duo

    Cisco Duo breakdown of push phishing / push bombing with response guidance

  • BleepingComputer

    Coverage of Lapsus$ and Yanluowang using MFA fatigue against Microsoft, Cisco, and Uber

  • Proofpoint

    MFA fatigue attack overview and recommendation to adopt number-matching and phishing-resistant MFA

  • CISA

    CISA guidance on phishing-resistant MFA including push bombing as a bypass vector

  • Dark Reading

    Uber breach analysis attributing attack to Lapsus$ via MFA bombing of external contractor

Related techniques

Same stage

  • Credential Theft
  • SIM Swap
  • Clipboard Hijacking
  • Malicious App Installation
  • Overlay Attack
  • +9 more

Similar defense

  • Data Breach Harvesting
  • Account Takeover
  • Account Recovery Backdoor
  • MFA Device Registration