Resource icon

What is MFA fatigue or push bombing?

MFA fatigue, also called push bombing, is an attempt to overwhelm someone with sign-in approval requests until they accept one by mistake or to make the alerts stop. A caller may pretend to be support and ask the person to approve the next prompt.

Quick example​

Your phone receives ten authenticator prompts while you are not signing in. Someone then calls and says approving the next request will stop a system error. That approval could authorize their login.

What to do​

Deny prompts you did not initiate. Open the account directly, review activity and change the password if the requests repeat or the account shows suspicious changes. Tell your IT team if it is a work account. A request is not evidence that the attacker has completed a login; an unfamiliar successful sign-in is more serious. Microsoft's sign-in guidance says to deny unexpected requests.

Practical distinction​

When a prompt includes a number to match, compare it only with the number shown in a sign-in you initiated. A caller reading a number aloud is not proof they are support.
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack