TL;DR: MFA fatigue attacks use repeated push prompts, stolen credentials, and user annoyance to turn approval-based MFA into a bypass path, according to WorkOS, while defenders need number matching, rate limits, context-aware checks, and phishing-resistant authentication. Human approval is not a dependable security boundary when attackers can force the decision loop.
At a glance
What this is: This is a WorkOS analysis of MFA fatigue attacks and how repeated push prompts can turn human approval into an access bypass.
Why it matters: It matters because IAM teams still relying on approval prompts need controls that reduce prompt abuse, detect suspicious authentication bursts, and move toward phishing-resistant MFA.
Context
MFA fatigue attacks exploit the assumption that a human can reliably distinguish a legitimate login prompt from an attack when the prompts arrive in rapid succession. In practice, the security model breaks when approval becomes a noise-management task instead of a deliberate verification step, especially for NHI-adjacent identity flows that still depend on human confirmation.
The article focuses on how repeated MFA requests, stolen passwords, and social engineering combine into a compromise chain rather than a single technical exploit. That makes the issue an identity governance problem as much as an authentication problem, because the trust boundary sits at the approval step and attackers target the person operating it.
Key questions
Q: How should security teams reduce the risk of MFA fatigue attacks?
A: Security teams should remove approval-based MFA from high-risk access paths, replace it with cryptographic authentication, and reduce the privileges attached to any successful session. They should also detect repeated prompt events as attack signals, not user noise, and trigger response when requests spike unexpectedly.
Q: Why do repeated MFA prompts create account takeover risk?
A: Repeated prompts work because they pressure the user into a fast decision. The attacker is not bypassing the factor directly. They are overwhelming the person behind it until one approval completes the session. That is why human vigilance alone is not a durable control and why organisations need context-aware step-up policies and stronger factors for higher-risk access.
Q: What are the warning signs that MFA fatigue is in progress?
A: Look for many MFA requests in a short time, repeated denials or cancellations, unusual access geography, and a successful approval after a burst of failures. Those signals show the attacker is probing the human decision loop rather than exploiting a technical flaw.
Q: Should organisations replace traditional MFA with passkeys and adaptive controls?
A: For most programmes, yes for the primary path and no for everything else. Passkeys should become the preferred method where device support allows it, while adaptive controls decide when extra checks are needed. Traditional MFA can remain as fallback, but it should no longer be the default for every login.
Technical breakdown
How repeated MFA prompts become a bypass path
MFA fatigue attacks start after the attacker already has valid credentials, then repeatedly triggers push notifications until the user approves one. The tactic works because the authentication step is no longer a single verification event but a pressure campaign that exploits habituation, confusion, and interruption. This is not a protocol failure in MFA itself. It is a failure in the approval model, where a user becomes the final decision gate under conditions that an attacker can manipulate at scale. Number matching, rate limiting, and device or location context all reduce the odds that a blind approval succeeds.
Practical implication: treat approval-only MFA as a control with a known abuse path and add anti-spam and anti-blind-approval safeguards.
Why phishing-resistant MFA changes the attack surface
Phishing-resistant MFA methods, such as hardware security keys, platform authenticators, and passkeys, bind the authentication ceremony to the legitimate device or cryptographic assertion rather than a repeatable push prompt. That matters because MFA fatigue depends on remote, replayable approval requests that can be induced from anywhere once credentials are stolen. When authentication is bound to possession of a device and an origin-aware challenge, the attacker loses the ability to overwhelm the user with endless prompts. The security gain is not just stronger authentication. It is removal of the prompt-spam mechanic itself.
Practical implication: prioritise phishing-resistant methods for user populations most exposed to credential theft and push-based authentication abuse.
What monitoring has to detect before compromise lands
Detection has to look for the pattern behind the nuisance: repeated MFA requests, failed approvals, unusual geographies, off-hours activity, and a successful approval following a burst of denials or cancellations. Those signals matter because MFA fatigue is usually the second step in a chain that begins with credential theft. Security teams therefore need correlation across identity provider logs and SIEM telemetry, not just alerts on individual failed logins. UBA can add context, but the core requirement is to recognise prompt abuse as an active compromise attempt rather than user error.
Practical implication: alert on repeated prompts plus post-burst approval events, then investigate the account as a likely compromise candidate.
Threat narrative
Attacker objective: The attacker wants the user to approve one prompt so the account can be taken over and used for broader compromise.
- Entry begins when the attacker obtains a valid username and password through phishing, brute force, or credential stuffing.
- Credential abuse follows as the attacker repeatedly submits login attempts, generating a stream of MFA prompts on the victim's device.
- Escalation occurs when the user finally approves a request, often because of frustration, confusion, or trust in the prompt.
- Impact is account compromise, which can then lead to lateral movement, data exfiltration, or privilege escalation.
Breaches seen in the wild
- Cisco Yanluowang breach 2022: A password synced to a personal Google account plus vishing and MFA fatigue opened Cisco's VPN; the attacker then abused machine accounts.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Human approval is not a stable authentication boundary: MFA fatigue succeeds because the control assumes a person can act as a reliable verifier under pressure. That assumption breaks when attackers can shape timing, repetition, and annoyance until approval becomes a relief action rather than a trust decision. The implication is that approval-based MFA must be treated as a user interface control, not a durable security boundary.
Prompt spam is an identity governance failure, not just an authentication nuisance: The real weakness is the organisation's tolerance for unlimited challenge generation against a single identity. Access governance that does not rate-limit authentication attempts leaves the human to absorb the attack. That shifts the burden of control onto the least reliable part of the chain, which is why MFA fatigue belongs in identity governance discussions, not only in helpdesk procedures.
Ephemeral prompt abuse creates prompt debt: Repeated push notifications accumulate risk even when no single request looks malicious. This is a useful concept for teams thinking about authentication telemetry, because the threat is the volume and cadence of prompts, not just the final approval event. Practitioners should recognise that prompt debt only exists when systems allow repeated challenges without stronger contextual checks.
Phishing-resistant MFA closes the remote-approval loophole: Passkeys, platform authenticators, and hardware keys change the governance model because the attacker can no longer rely on a human tapping through a barrage of prompts. That shifts the control from behavioural resistance to cryptographic binding and device possession. For identity programmes, this is the cleanest way to remove the attack primitive rather than trying to train users out of fatigue.
From our research library:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
What this signals
Human approval checks need a shorter trust window: MFA fatigue shows that the control failure is not the existence of a second factor, but the ability to keep asking the same person until a tired answer arrives. Identity teams should treat repeated prompt generation as a policy violation condition, not normal noise.
Security programmes that still rely on push approval need to separate usability from assurance. The practical shift is toward controls that make silent, repeated challenge abuse observable and that remove the attacker's ability to generate endless prompts against one identity.
For practitioners
- Enforce number matching on push MFA Replace blind approve or deny prompts with number matching so a user must see and confirm the login challenge. That reduces the value of repeated notifications and makes remote spamming far less effective.
- Rate-limit repeated authentication prompts Cap the number of MFA requests per identity in a short window and suspend or challenge accounts that trigger excessive failures. The goal is to stop prompt flooding before the user is worn down.
- Move high-risk users to phishing-resistant MFA Use passkeys, platform authenticators, or hardware security keys for users who face frequent credential theft or elevated access exposure. These methods remove the remote push-approval loop entirely.
- Correlate prompt bursts with suspicious access attempts Use identity provider logs and SIEM alerts to flag multiple MFA requests, repeated denials, and approvals that follow a burst of failures. Investigate those accounts as likely compromise cases.
Key takeaways
- MFA fatigue works because attackers can turn a legitimate approval step into a pressure campaign against the user.
- The article's core evidence chain starts with stolen credentials and ends with account compromise, often before defenders notice the prompt pattern.
- Number matching, rate limits, and phishing-resistant MFA are the controls that reduce the attack's success path most directly.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | MFA fatigue is an authentication abuse pattern that bypasses approval-based controls. |
| NHI-10 — Human Use of NHI | The attack succeeds by manipulating a human into approving a non-human authentication event. | |
| Recommendation — Replace blind approval flows with phishing-resistant authentication and anti-spam controls. Reduce human approval dependence where NHI authentication can be cryptographically bound. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Repeated prompts expose weak authorisation handling around identity access requests. |
| Recommendation — Apply access authorisation controls that limit repeated authentication attempts and approval abuse. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle controls cover MFA handling, retry exposure, and credential-based access. |
| Recommendation — Use authenticator management to enforce strong MFA methods and constrain repeated challenge requests. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes credential theft followed by post-compromise movement. |
| Recommendation — Map prompt abuse to credential access and monitor for movement after a successful approval. | ||
Key terms
- MFA Fatigue Attack: An MFA fatigue attack is a social engineering technique that bombards a user with repeated authentication prompts until they approve one out of annoyance, confusion, or urgency. The attacker usually starts with stolen credentials, then uses the approval flow itself to obtain access.
- Phishing-Resistant MFA: Phishing-resistant MFA uses authentication factors that cannot be easily replayed, intercepted, or socially engineered. In regulated environments, this usually means device-bound or cryptographic methods rather than push prompts or SMS codes, because the control must hold up under realistic attack conditions.
- Number Matching: Number matching is an MFA method that requires the user to enter or confirm a number shown on the login screen. It reduces blind approvals by linking the approval to the specific session, which makes random taps or reflexive acceptance far less effective.
- Credential Stuffing: Credential stuffing is an attack that uses stolen username and password pairs from previous breaches to try logging into other services. It works because many people reuse credentials, and because the login attempt uses valid information, it can look ordinary until the surrounding behavior gives it away.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org