Share This:

MFA was supposed to be a virtual panacea. For a while, it worked well. But attackers found a reliable workaround that requires no sophisticated malware or cryptographic expertise—just patience and an understanding of human behavior.

MFA fatigue attacks, also called push notification bombing, flood employees with authentication requests until someone finally taps ‘Approve.’ The technique remains one of the most effective tactics in today’s threat landscape.

Because it exploits human behavior instead of technical vulnerabilities, MSPs must help clients understand that not all MFA methods offer equal protection. Many organizations rely on weaker options than they realize.

Why MFA fatigue attacks remain effective

This approach remains inexpensive, scalable, and highly effective.

“Any organization using push approvals at scale should assume they are a target,” says Yassine Maizi, founder and editor of cybersecurity education publication SafeStackPro. “If they are not detecting it, that’s not necessarily proof attacks are not happening.”

Omair Manzoor, founder and CEO of ioSENTRIX, a CREST-accredited penetration testing and red team firm, explains why the tactic succeeds so often: “The employee sees ten, twenty, thirty prompts in rapid succession. Some approve just to make it stop. Some approve because they assume it’s a system glitch. Some approve at 2 AM when they’re half asleep.” In ioSENTRIX’s social engineering assessments, approval rates range from 15 to 25 percent when push bombing continues for several hours. Success rates increase during early mornings and late evenings.

Weak MFA methods create additional risk

Alan DeKok, CEO of InkBridge Networks and founder of the FreeRADIUS project, describes the flaw in push-based MFA bluntly:

“Push MFA turns authentication into ‘can I annoy you until you click yes?’ That works great for attackers because humans eventually optimize for getting the pop-ups to stop.”

His assessment of SMS-based MFA is equally direct: “If MFA is a code sent by SMS, then it’s only as secure as the teenager at the shopping mall phone booth. It is trivial to clone someone’s SIM card or convince a carrier to issue a new one. SMS MFA is better than nothing, but it should not be treated as serious protection for privileged accounts.”

Joshua Copeland, adjunct professor of information technology at Tulane University and a cybersecurity director with more than 25 years of experience, says the problem is becoming harder—not easier—to contain. “Push bombing is effective because attackers leverage repetition, strategic timing, confusion, and sometimes impersonate help desk personnel via phone calls,” he says. “Ultimately, employees may approve a request to halt persistent notifications. They often do so under the false impression that approval is part of a legitimate IT process. This represents not only a user-awareness issue, but also a failure in control design.”

Copeland notes that Microsoft continues to identify MFA fatigue attacks as a growing threat. Google’s M-Trends 2026 report also highlights the rising use of interactive social engineering to bypass traditional MFA.

Why MSPs face greater risk

For MSPs, the risk is amplified by their position in the supply chain.

“A single MSP technician’s account often has privileged access to dozens or hundreds of client environments,” Manzoor says. “We have assessed MSP environments where a single compromised technician credential provided administrative access to over fifty client tenants.”

DeKok adds an important point: push bombing is usually not the first stage of an attack.

“If a client is seeing it, they may already have a phished password, a compromised session or token, or an attacker inside the email or reset channel.”

In other words, repeated MFA prompts may signal that an attacker already cleared an earlier hurdle.

Moving beyond push-based MFA

All four experts interviewed by SmarterMSP recommend the same long-term solution: phishing-resistant MFA, specifically FIDO2 security keys and passkeys.

“Passkeys or FIDO2 hardware keys aren’t a nice-to-have anymore—they’re the real answer, because there’s no prompt to approve in the first place,” Maizi says. “Nothing to bomb.”

Manzoor explains why:

“FIDO2 and passkeys are cryptographically bound to the legitimate service. An attacker cannot trigger a FIDO2 prompt remotely. There is no prompt to approve or deny. The attack simply does not work because the protocol eliminates the human decision point that push bombing exploits.”

Copeland recommends a phased migration, starting with administrators, help desk staff, executives, finance teams, and remote-access users.

“Focus on accounts with the highest potential for organizational impact, rather than delaying until a companywide rollout is feasible.”

Interim controls MSPs should implement now

Organizations that cannot immediately adopt passkeys or FIDO2 keys can still reduce risk.

The experts consistently recommend:

  • Enabling number matching
  • Rate-limiting push attempts so excessive requests trigger lockouts and SOC alerts
  • Adding geolocation context to prompts
  • Eliminating weak fallback methods where possible

“Attackers will simply target the weakest available method,” Manzoor says.

He also highlights a step many MSPs overlook:

“Audit your own technicians’ MFA configurations before auditing your clients. If your technicians are still on push-based MFA with SMS fallback, you are the weakest link in every client’s security chain.”

Detection and user awareness still matter

Training remains a critical part of the defense strategy.

“The mitigation that actually works—though it’s boring—is training people to treat an MFA prompt they didn’t request as a sign something’s already wrong, not an annoyance to dismiss,” Maizi says.

Tools such as Barracuda XDR support this effort by continuously monitoring identity-related activity. The platform can detect warning signs that Copeland highlights, including repeated push requests, geographically inconsistent logins, new device enrollments, and successful approvals after multiple denials.

Detecting these events early helps security teams respond before attackers fully compromise an account.

Security should reduce human error—not depend on it

Copeland’s closing principle is especially relevant for MSPs:

“The objective should not be to rely on employees as human firewalls. Authentication systems should be designed to minimize the need for employees to make ambiguous security decisions—particularly when they are interrupted, distracted, or under pressure. Robust authentication should reduce reliance on human judgment rather than depend on it.”

In the end, MFA fatigue attacks succeed because they exploit people, not technology. The most effective defense is not adding more prompts. It’s removing opportunities for attackers to manipulate user decisions.

Photo: Amirul Syaidi / Shutterstock


Share This:
Kevin Williams

Posted by Kevin Williams

Kevin Williams is a journalist based in Ohio. Williams has written for a variety of publications including the Washington Post, New York Times, USA Today, Wall Street Journal, National Geographic and others. He first wrote about the online world in its nascent stages for the now defunct “Online Access” Magazine in the mid-90s.

Leave a reply

Your email address will not be published. Required fields are marked *

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.