MFA fatigue is a social engineering attack that exploits user frustration by bombarding victims with repeated authentication requests until they approve access just to stop the notifications. Understanding this threat is essential for anyone relying on multi-factor authentication as a security control.
MFA Fatigue
Most people are setting up MFA nowadays. It takes a huge step towards securing things, but it's not foolproof, and MFA fatigue is one example of that.
Passwords themselves are not a complete solution towards security. There are so many holes and problems with passwords: from credential replay attacks to stolen passwords to guessing passwords, there's a lot of problems. I'd say that the general populace really doesn't know how to have a correct password and be able to manage it correctly.
Multi-factor authentication, or MFA, takes a huge step towards securing things. Now it's not only something you know, that you have to type in, that could be easily given to other people, but it's also something you have, like your phone. So this multi-factor authentication really helps secure people's accounts, because they're going to have to have some sort of access to the phone, or to the electronic signals that communicate back and forth to that phone.
But what they found is that if a user gets a lot of these MFA notifications, at some point in time they break down. For instance, let's say you had an app on the phone and it would have just a simple, do you want to accept? Are you trying to log into something? What you're going to do, if you're not trying to log into something, is reject that. But let's say it keeps happening again and again and again. They find that many people will start hitting that accept just to get rid of the message. They get so frustrated, they don't want to deal with it anymore, so they hit accept thinking that it will go away. Really, their problems are just beginning at that point in time.
So this is MFA fatigue. What you're doing is you're wearing down the victim to the point at which they just accept whatever MFA message is coming up. Here's the attack card on MFA fatigue: you're just overwhelming the user with lots of MFA requests to the point where they're going to hit the accept on the phone because they're so frustrated.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →