Technique
MFA Fatigue Attack
Also known as: Push Bombing, Push Harassment, MFA Prompt Bombing, Push Fatigue, Push Phishing
Attacker who already possesses stolen credentials repeatedly triggers MFA push notifications to the victim's device -- sometimes hundreds in succession -- until the victim approves one out of frustration, confusion, or accidental tap. Often combined with social-engineering calls where the attacker p…
Defense
How to defend against this
How to spot it
- Receiving rapid-fire MFA push notifications you did not initiate
- Unexpected phone call from IT support asking you to approve an MFA prompt
- MFA prompts arriving at unusual hours or from unfamiliar geographic locations
- Seeing a login attempt notification for a service you are not currently accessing
Tools you can use
Further reading
BeyondTrust
Definition, attack flow, and defense strategies for MFA fatigue attacks including Uber/Lapsus$ case study
Cisco Duo
Cisco Duo breakdown of push phishing / push bombing with response guidance
BleepingComputer
Coverage of Lapsus$ and Yanluowang using MFA fatigue against Microsoft, Cisco, and Uber
Proofpoint
MFA fatigue attack overview and recommendation to adopt number-matching and phishing-resistant MFA
CISA
CISA guidance on phishing-resistant MFA including push bombing as a bypass vector
Dark Reading
Uber breach analysis attributing attack to Lapsus$ via MFA bombing of external contractor