🔔 MFA Fatigue Attacks: How Push Notification Bombing Bypasses 2FA (2026)
On this page
- What Is MFA Fatigue?
- How a Push Bombing Attack Works: Step by Step
- Real-World MFA Fatigue Incidents
- Why Push-Based 2FA Is the Most Exploitable Form of MFA
- Three Steps to Eliminate Your Fatigue Attack Exposure
- Storing TOTP and Passkeys Securely Across Devices
- What to Do If You Receive Unexpected Push Notifications Right Now
- FAQs
In September 2022, an Uber contractor received over 100 Microsoft Authenticator push requests in a single hour. An attacker already had his credentials — all they needed was one tap. When he finally approved a notification to stop the alerts, the attacker walked straight into Uber’s internal network without touching a phishing page or intercepting a single code.
What Is MFA Fatigue?
Multi-factor authentication fatigue is a social engineering technique that targets the human side of authentication rather than its cryptography. The attacker already has your username and password — obtained from a data breach, a prior phishing email, or credential-stuffing software. The password alone is not enough because your account requires a second factor. So the attacker manufactures the second factor by triggering it relentlessly until you provide it for them.
Definition: MFA fatigue (push bombing) is an attack in which a threat actor who holds a victim’s password repeatedly generates 2FA push notification requests to the victim’s device. By overwhelming the victim with approval prompts, the attacker attempts to provoke an accidental approval, exploit a moment of confusion, or wear down the victim’s resistance until they tap “Approve” simply to make the notifications stop. Push-based 2FA is specifically vulnerable because it requires no secret knowledge from the victim — only a tap on a screen.
How a Push Bombing Attack Works: Step by Step
- Credential acquisition. The attacker obtains your username and password. This is easier than most people assume: Have I Been Pwned indexes over 13 billion breached credentials. If you reuse passwords across sites, your credentials from a years-old forum breach may already be in active circulation.
- Triggering the 2FA prompt. The attacker attempts to log in with your credentials. The service rejects the password alone and sends a push notification to your registered authenticator app (Microsoft Authenticator, Duo, Okta Verify, or similar).
- Repetition and social pressure. The attacker immediately repeats the login attempt, triggering another push. Then another. Determined attackers can send dozens of notifications per minute. Many simultaneously send SMS or WhatsApp messages impersonating IT support: “You have a pending security notification. Please approve it to prevent account lockout.”
- Exploitation of the approval. The victim taps “Approve” — from exhaustion, distraction, genuine belief it is a system glitch, or simply to stop the alerts. The attacker is immediately authenticated. The full operation often takes under 30 minutes.
Real-World MFA Fatigue Incidents
Push bombing is not theoretical. It has breached household-name organisations in documented incidents:
| Incident | Year | Method | Outcome |
|---|---|---|---|
| Uber | 2022 | 100+ Authenticator push requests to an external contractor over one hour | Full internal network access; internal tools, Slack, and source code compromised |
| Cisco Talos | 2022 | Push bombing combined with vishing calls claiming IT support needed the contractor to approve | VPN access obtained; attacker maintained persistence for weeks undetected |
| Twilio | 2022 | Employees directed to a fake Okta page via SMS phishing; push requests triggered on real accounts | Customer data stolen including Authy app phone number registrations |
| MGM Resorts | 2023 | IT helpdesk social engineering followed by MFA fatigue on the reset account | Estimated $100M+ in losses; slot machines and hotel systems offline for days |
The pattern is consistent across incidents: the attacker does not break the 2FA system. They break the person holding the phone.
Why Push-Based 2FA Is the Most Exploitable Form of MFA
Not all second factors carry equal risk. Push notifications are the most convenient form of MFA, and that convenience is precisely the attack surface. Comparing 2FA methods by their fatigue and phishing resistance makes the hierarchy clear:
| 2FA Type | Fatigue Attack? | Phishing Resistant? | Notes |
|---|---|---|---|
| Push notification (Duo, Authenticator, Okta Verify) | Yes — trivially | No | Only requires a tap; victim provides no knowledge; nothing to intercept |
| SMS one-time code | No push to spam | No | Interceptable via SIM swap; real-time phishing proxies capture codes live |
| TOTP authenticator code (Google Authenticator, NordPass) | No — nothing to push | Partial | Victim must actively type a code; still capturable by real-time phishing proxy |
| Passkey (FIDO2/WebAuthn) | No | Yes — fully | Domain-bound cryptographic credential; cannot be used on fake sites; immune to both vectors |
| Hardware security key (YubiKey) | No | Yes — fully | Physical presence required; strongest available protection |
In 2024, CISA published an advisory explicitly recommending that organisations move away from push-based MFA toward FIDO2 passkeys and hardware keys, calling push notifications “susceptible to social engineering and prompt fatigue attacks.” The advisory names push bombing as a primary driver of enterprise account compromises.
Three Steps to Eliminate Your Fatigue Attack Exposure
1. Switch from Push Notifications to TOTP Codes
TOTP (Time-based One-Time Password) codes are the six-digit numbers generated every 30 seconds by authenticator apps. Unlike push notifications, there is nothing for an attacker to trigger: no notification arrives on your phone, no button asks for approval. To get past TOTP, an attacker must trick you into actively typing a current code on a fake site — a harder attack that requires real-time interception, not passive waiting for a tap.
Wherever your accounts offer a choice between “push notification” and “authenticator app (TOTP),” choose TOTP. Typing six extra digits is a small inconvenience for eliminating an entire attack category.
2. Enable Number Matching if Push Is Mandatory
If you cannot switch to TOTP — for example, your employer mandates Microsoft Authenticator push — check whether number matching is enabled. This feature displays a two-digit number on your login screen that you must enter in the authenticator app before you can approve. An attacker sending spam push notifications cannot provide the correct number because they cannot see your screen. Microsoft, Okta, and Duo all support number matching; it is the minimum acceptable enterprise configuration for push-based 2FA.
3. Move Your Highest-Value Accounts to Passkeys
Passkeys are immune to both MFA fatigue and phishing because they are domain-bound cryptographic credentials. An attacker cannot trigger a passkey approval remotely — authentication happens on your device, using your biometric or PIN, in response to a challenge from the exact registered domain. There is no push to spam and no code to intercept.
Enable passkeys on your Google account, Apple ID, GitHub, and financial accounts first. These are the accounts that, if compromised, give an attacker the most leverage over everything else you own.
Storing TOTP and Passkeys Securely Across Devices
Switching to TOTP raises a practical question: where do you store dozens of TOTP secrets securely, synced across all your devices, with a safe backup if you lose your phone? A standalone authenticator app on one device is a single point of failure. A password manager that handles TOTP codes solves this.
NordPass stores TOTP secrets alongside passwords and passkeys inside its zero-knowledge encrypted vault. This gives three practical advantages over a standalone authenticator app:
- Cross-device sync. Your TOTP codes are available on every device where NordPass is installed — not locked to a single phone you might lose or replace.
- Encrypted backup. If you lose your phone, you do not lose your entire 2FA setup. Your TOTP secrets are recoverable from any device signed in to your NordPass account.
- Single vault for all credential types. Passwords, TOTP codes, and passkeys in one encrypted vault means one audit surface, one backup strategy, and one breach-monitoring system watching all of them.
NordPass also monitors your email addresses against new data breaches in real time. This matters because MFA fatigue attacks always begin with a stolen password — the same kind of credential exposure NordPass breach monitoring is designed to surface before attackers can exploit it. Addressing both sides of the problem (hardening your 2FA type and monitoring for credential exposure) from one tool is more effective than managing them separately.
The free tier covers unlimited passwords and TOTP codes on one device. Premium adds multi-device sync and real-time breach monitoring for under £2/month.
What to Do If You Receive Unexpected Push Notifications Right Now
- Deny immediately. Never approve a push you did not personally initiate within the last 60 seconds.
- Change your password right away. An unsolicited push means an attacker currently holds your password. Change it before they try another approach.
- Check your active sessions. Google, Microsoft, and most major services show active login sessions under Security settings. Revoke any sessions from unfamiliar locations or devices.
- Switch your 2FA method. Use the incident as the prompt to move that account from push to TOTP or a passkey before the attacker tries again.
Affiliate disclosure: Some links in this article are affiliate links. If you sign up through them we may earn a small commission at no extra cost to you. Our password generator is free to use and we only recommend tools we would use ourselves. See our full affiliate disclosure.
FAQs
What is MFA fatigue?
MFA fatigue (push bombing or prompt bombing) is an attack in which a threat actor who already holds a victim’s password repeatedly triggers push-based 2FA approval requests. The goal is to provoke an approval through exhaustion, distraction, or confusion rather than by breaking any technical control. It became prominent after the 2022 Uber and Cisco Talos breaches, both executed entirely via push bombing without any malware or code exploitation.
Does MFA fatigue work against TOTP codes?
No. TOTP codes cannot be push-bombed because there is no push to send. The attacker cannot trigger a notification on your phone; they would need to trick you into actively entering a current six-digit code on a fake site. That is a separate, harder attack requiring real-time interception — and it does not scale through volume and repetition the way push bombing does. Switching any account from push to TOTP eliminates fatigue attacks entirely for that account.
How do I turn off push 2FA and switch to TOTP?
The process varies by service, but the general path is: Account Settings → Security → Two-Factor Authentication → look for “Authenticator App” or “TOTP” as an alternative to push notifications. You will be shown a QR code to scan with your authenticator app (Google Authenticator, Authy, or NordPass). Scan it, confirm a code, and save your backup codes. For Microsoft accounts managed by an employer, your IT administrator controls the available 2FA methods — request that they enable TOTP or at minimum activate number matching for push approvals.
Is MFA fatigue the same as SIM swapping?
No. SIM swapping targets SMS-based 2FA by convincing your mobile carrier to reassign your phone number to an attacker’s SIM, letting them intercept your SMS codes. MFA fatigue targets push-based 2FA by spamming your authenticator app until you tap Approve. Both are social engineering attacks that bypass 2FA without breaking cryptography, but they exploit different 2FA mechanisms. Both are eliminated by switching to TOTP authenticator codes or passkeys.
Are enterprise accounts more at risk from MFA fatigue than personal accounts?
Enterprise accounts are higher-value targets, but the mechanism applies equally to personal accounts. Any account protected by push-based 2FA — personal Google account, personal Microsoft account, consumer banking apps using push approval — is vulnerable. Uber, Cisco, and MGM were high-profile because the downstream damage was larger, not because the technique is enterprise-specific. Personal email and financial accounts are targeted with the same method at scale; the incidents are less newsworthy but more numerous.