TechKnowSurge
VideoSecurityFree

MFA Fatigue

MFA fatigue is a social engineering attack that exploits user frustration by bombarding victims with repeated authentication requests until they approve access just to stop the notifications. Understanding this threat is essential for anyone relying on multi-factor authentication as a security control.

Complete this video to capture a CTF flag worth 1 point.

About this video

Passwords alone have long been considered an inadequate security control, vulnerable to credential replay attacks, theft, and guessing. Multi-factor authentication addresses many of these weaknesses by adding a second layer of verification tied to a physical device, meaning an attacker cannot gain access through stolen credentials alone. This additional layer has made MFA a widely adopted standard across both personal and enterprise environments, but its effectiveness depends heavily on user behavior. MFA fatigue exploits that dependency by turning a security feature into an attack vector. Rather than attempting to bypass MFA technically, an attacker repeatedly sends push notification approval requests to the target's device. As the volume of notifications increases, users become frustrated and disengaged, eventually approving a request just to stop the interruptions, without verifying whether the login attempt is legitimate. That single approval grants the attacker full access, and the attack succeeds entirely through psychological wear-down rather than technical exploitation. Recognizing this pattern is a critical step in defending against it.

What you'll learn

What's covered

MFA Fatigue

Key terms

Multi-Factor Authentication
MFA
An authentication method that requires users to provide two or more verification factors to gain access.
Authentication
The process of verifying the identity of a user, device, or system.
Social Engineering
A manipulation technique that exploits human psychology to trick individuals into revealing confidential information.
MFA Fatigue
An attack technique where an adversary overwhelms a user with repeated MFA push notifications, manipulating them into approving an unauthorized access request out of frustration.

Topics

Mfa Fatigue Multi Factor Authentication Social Engineering Identity And Access Management Cybersecurity Push Notification Attacks

Transcript

Most people are setting up MFA nowadays. It takes a huge step towards securing things, but it's not foolproof, and MFA fatigue is one example of that.

Passwords and MFA

Passwords themselves are not a complete solution towards security. There are so many holes and problems with passwords: from credential replay attacks to stolen passwords to guessing passwords, there's a lot of problems. I'd say that the general populace really doesn't know how to have a correct password and be able to manage it correctly.

Multi-factor authentication, or MFA, takes a huge step towards securing things. Now it's not only something you know, that you have to type in, that could be easily given to other people, but it's also something you have, like your phone. So this multi-factor authentication really helps secure people's accounts, because they're going to have to have some sort of access to the phone, or to the electronic signals that communicate back and forth to that phone.

MFA fatigue

But what they found is that if a user gets a lot of these MFA notifications, at some point in time they break down. For instance, let's say you had an app on the phone and it would have just a simple, do you want to accept? Are you trying to log into something? What you're going to do, if you're not trying to log into something, is reject that. But let's say it keeps happening again and again and again. They find that many people will start hitting that accept just to get rid of the message. They get so frustrated, they don't want to deal with it anymore, so they hit accept thinking that it will go away. Really, their problems are just beginning at that point in time.

So this is MFA fatigue. What you're doing is you're wearing down the victim to the point at which they just accept whatever MFA message is coming up. Here's the attack card on MFA fatigue: you're just overwhelming the user with lots of MFA requests to the point where they're going to hit the accept on the phone because they're so frustrated.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →