Get fresh insights, pro tips, and thought starters–only the best of posts for you.
MFA bombing is a social engineering technique where attackers repeatedly send multi-factor authentication (MFA) requests to a user’s device until the user approves one. Also known as MFA fatigue, this attack targets human behavior rather than technical vulnerabilities. As organizations increasingly adopt MFA to protect accounts, attackers use MFA bombing to exploit notification overload and gain unauthorized access using stolen credentials.
Attackers often target users rather than the MFA technology itself. After obtaining valid credentials through phishing, credential theft, or data breaches, they repeatedly trigger authentication requests until a user approves one.
Common reasons these attacks succeed include:
Because the attack exploits human behavior, organizations should combine strong authentication controls with user awareness training.
Understanding the attack sequence helps security teams identify suspicious authentication behavior before an account becomes compromised.
A typical attack follows these steps:
Once access is granted, attackers may attempt lateral movement, data access, or privilege escalation depending on the compromised account’s permissions.
Repeated authentication requests often indicate more than a simple login mistake. Security teams should investigate unusual authentication patterns before they develop into larger incidents.
The following indicators commonly appear during MFA bombing attempts:
| Warning sign | Why it matters |
|---|---|
| Frequent MFA prompts | May indicate repeated login attempts |
| Login requests at unusual hours | Could signal unauthorized access attempts |
| MFA approvals users do not recognize | Suggest a possible credential compromise |
| Authentication attempts from unfamiliar locations | May indicate attacker activity |
| Multiple denied approval requests | Often precede successful fatigue attacks |
Monitoring these signals can help organizations detect and contain suspicious activity earlier.
Defending against MFA bombing requires stronger authentication controls and improved visibility into user activity. Security teams should focus on reducing opportunities for accidental approvals.
Common security measures include:
Together, these controls make it significantly harder for attackers to abuse compromised credentials.
Unexpected MFA requests may indicate a broader account compromise attempt. Once users report suspicious prompts, security teams need visibility into affected devices and related security events.
Hexnode XDR helps analysts review incident details, examine endpoint activity, investigate suspicious events, and gather context from affected devices through a centralized interface.
Endpoint visibility combined with strong authentication controls can help organizations respond more effectively to suspicious authentication activity.
Yes. Any account that uses push-based MFA can become a target, including email, banking, cloud, and social media accounts.
Teams should review authentication logs, investigate recent account activity, and reset credentials if compromise is suspected.
Yes. Security keys and passkeys provide stronger protection because they do not rely on simple approval prompts.