By NHI Mgmt Group Editorial TeamBased on Axiad: “The Growing Problem with MFA Fatigue Attacks (And What You Can Do About It)” (September 16, 2025)

TL;DR: MFA fatigue attacks flood users with push notifications until one is approved, according to Axiad, and a report from Expel found that 80% of successful business account compromise attacks occurred on accounts already protected by MFA. Push-based MFA is only as strong as the user's ability to resist manipulation.


At a glance

What this is: This is Axiad's analysis of MFA fatigue attacks, where attackers overload users with push prompts to trigger a mistaken approval and bypass authentication controls.

Why it matters: It matters because IAM teams cannot treat MFA as resistant by default if approval prompts can be socially engineered into access grants.

By the numbers:

  • 80% of successful business account compromise attacks occurred on accounts already protected by MFA, according to Expel research cited by Axiad.

Context

MFA fatigue attacks target the human approval step in push-based authentication. The underlying problem is not that MFA is absent, but that repeated prompts can be used to wear users down until they approve a login they did not initiate.

For IAM programmes, this is a design and governance issue rather than a simple user-awareness problem. If authentication depends on a user recognising noise under pressure, the control assumes more judgement than it can reliably receive in a real attack.

The article frames a common failure pattern: organisations deploy MFA, yet still leave room for approval bombing, weak alerting, and poorly constrained authentication methods. That makes the issue typical across environments that rely heavily on push approval.


Key questions

Q: What breaks when push-based MFA is exposed to repeated notification attacks?

A: The control breaks when approval becomes automatic instead of deliberate. Repeated prompts can condition users to accept one just to stop the noise, which means the second factor no longer proves genuine intent. In that state, the attacker is no longer defeating MFA cryptographically. They are exploiting the approval workflow itself.

Q: Why do push notifications make account takeover easier for attackers?

A: Push notifications make account takeover easier because they turn authentication into a repeated decision point that an attacker can manipulate. If the attacker already has credentials, the remaining barrier is often user hesitation, not technical resistance. Repetition, urgency, and distraction can be enough to force a mistaken approval and open the session.

Q: What are the signs that MFA fatigue is being used against users?

A: Common signs include a burst of push requests, approvals that happen after several denials, unexpected enrolment of a new device, and suspicious sign-ins that align with user distraction or help desk impersonation. Security teams should treat these as correlated indicators of pressure-based authentication abuse, not isolated login events.

Q: How should organisations reduce MFA-related account takeover risk?

A: Start by replacing the weakest factors on the highest-risk accounts, then remove recovery paths that depend on shared secrets or easily intercepted delivery channels. Pair that with risk-based step-up, strong offboarding, and continuous review of fallback access. The goal is to make takeover harder without turning authentication into a usability failure.


Technical breakdown

How push fatigue attacks bypass approval-based MFA

Push-based MFA asks a user to approve a login request on a trusted device. In an MFA fatigue attack, the attacker first obtains credentials, then repeatedly triggers prompts until the user accepts one out of annoyance, confusion, or a mistaken belief that the system is malfunctioning. The control failure is not cryptography, but the dependence on human interpretation of repeated prompts. Once approval is given, the attacker often inherits the authenticated session without needing to defeat the second factor in the normal sense.

Practical implication: treat repetitive push prompts as an abuse signal, not as routine authentication noise.

Why phishing-resistant authenticators change the trust model

Phishing-resistant authenticators reduce reliance on shared secrets or simple approval gestures by binding authentication to cryptographic proof rather than user reflex. The article points toward public key cryptography and passwordless methods as stronger alternatives because they narrow the attacker's ability to replay, coerce, or trick the user into granting access. This matters because the core weakness in push fatigue is not the presence of a second factor, but the fact that the factor can still be socially engineered at the decision point.

Practical implication: move high-risk users and applications toward authenticators that cannot be approved through notification spam.

How session and method controls limit blast radius

MFA fatigue becomes more dangerous when session duration is long, new device enrolment is weakly controlled, or multiple MFA methods are available without strong policy boundaries. Those conditions increase the time and pathways an attacker can exploit after an initial approval. Location changes, token theft, and suspicious user-profile changes are all signals that the authentication boundary is being stretched beyond its intended scope. In IAM terms, the issue is not just who authenticated, but how long that trust is allowed to persist.

Practical implication: tighten session scope, restrict MFA method choice, and trigger step-up checks on enrolment or context change.


Threat narrative

Attacker objective: The attacker wants a legitimate-looking authenticated session that bypasses the user's normal approval discipline and grants account access.

  1. Entry begins when an attacker obtains valid credentials through phishing or another credential theft method.
  2. The attacker repeatedly triggers MFA push requests, turning the authentication process itself into a pressure campaign.
  3. Escalation occurs when the user accepts one prompt, allowing the attacker to establish an authenticated session.
  4. Impact follows as the attacker gains access to the account or device and can move into sensitive applications or data.
  • Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
  • Cisco Yanluowang breach 2022: A password synced to a personal Google account plus vishing and MFA fatigue opened Cisco's VPN; the attacker then abused machine accounts.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Push fatigue is a governance failure in the authentication decision, not merely a user mistake. Repeated approval prompts turn the human into the weakest control point in the trust chain. When authentication can be worn down through repetition, the programme is assuming users will behave like deterministic policy engines, which they do not. The practitioner conclusion is that approval-based MFA cannot be treated as a sufficient control on its own.

Phishing-resistant authentication is the dividing line between resilient identity control and prompt management. The article's argument points toward cryptographic authenticators and passwordless methods because they remove the attacker’s ability to force a simple yes/no response from the user. That changes the control from persuasion-resistant to persuasion-dependent. The practitioner conclusion is that authenticator choice is a security architecture decision, not a convenience feature decision.

Repeated prompts expose a named concept we can call identity prompt fatigue. This is the condition where authentication noise becomes exploitable because the control is allowed to generate too many user decisions under pressure. It is especially dangerous when organisations normalise frequent prompts and do not treat them as an anomaly. The practitioner conclusion is that alert volume, not just alert content, must be governed.

Long sessions and broad MFA method choice expand the blast radius of a single mistaken approval. If access survives beyond the login moment and the user can enrol new methods or accept multiple factors without strong constraints, the attacker does not need a perfect attack path. The governance lesson is that authentication policy must control post-login persistence, not only initial entry.

Human awareness is necessary, but it cannot be the primary compensating control for weak push design. Training helps users recognise prompt bombing, but the underlying model still depends on a person making a security decision while under manipulation. The programme implication is that detection, policy boundaries, and cryptographic authenticators must carry more of the burden than awareness alone.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

Identity prompt fatigue: repeated push approvals are not just noisy UX, they are an exploitable control surface that turns human tolerance into an attack path. IAM teams should measure how often authentication depends on repeated user decisions and remove any design that rewards attacker persistence.

Push-based MFA remains useful, but only when the organisation treats approval as an exposed decision point rather than a security guarantee. That means narrowing session duration, restricting weaker methods, and moving sensitive access to cryptographic authenticators that cannot be worn down by notification spam.


For practitioners

  • Require phishing-resistant authenticators Prioritise public key based and passwordless methods for users who access sensitive systems, especially where push approval is currently the default factor.
  • Limit repeated MFA attempts Set thresholds that flag or block unusual volumes of MFA requests, because repetitive prompts are a core abuse pattern in fatigue attacks.
  • Constrain MFA method choice Restrict weaker methods such as SMS or email codes where stronger options are available, and remove fallback paths that attackers can steer users toward.
  • Trigger step-up on context change Require additional checks when IP address, device state, or user profile changes indicate that the original authentication context is no longer stable.
  • Review suspicious approvals quickly Investigate rapid approval events, repeated prompts, and new device enrolment together, because they often form the pattern that precedes account takeover.

Key takeaways

  • MFA fatigue attacks succeed by exploiting the human approval step, which means the weakness is the control design rather than the existence of MFA itself.
  • The article shows that successful account compromise can still happen on MFA-protected accounts when push prompts are used as the primary trust check.
  • Phishing-resistant authenticators, tighter method control, and narrower session scope are the controls most likely to reduce the impact of push-based abuse.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationPush MFA fatigue concerns the strength and usability of authenticators.
Recommendation — Prefer authenticators that resist phishing and prompt bombing, and reserve push approval for lower-risk contexts.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article focuses on whether authentication grants should be trusted after user approval.
DE.CM-01 — Networks and services are monitored to detect potential cybersecurity eventsRepeated prompt bursts and suspicious approvals are detection signals, not normal login behaviour.
Recommendation — Apply PR.AA-05 to constrain who can access what after authentication and reduce overbroad session trust. Monitor authentication event patterns for prompt storms, unusual approvals, and enrolment anomalies.
MITRE ATT&CKTA0006 — Credential AccessThe attack depends on credential theft followed by abusive access approval.
Recommendation — Map MFA fatigue activity to TA0006 and investigate credential theft paths before approval abuse begins.
OWASP ASVSV10 — OAuth and OIDCThe article's recommendations touch stronger federated and passwordless authentication patterns.
Recommendation — Use V10 to validate stronger federation and token-handling paths when replacing push-based MFA.

Key terms

  • MFA Fatigue Attack: An MFA fatigue attack is a social engineering technique that bombards a user with repeated authentication prompts until they approve one out of annoyance, confusion, or urgency. The attacker usually starts with stolen credentials, then uses the approval flow itself to obtain access.
  • Phishing-resistant Authenticator: An authentication factor that cannot be easily replayed, proxied, or tricked into disclosure by phishing. In practice, it uses public key cryptography and binds the authentication response to the legitimate origin and transaction context, reducing the value of stolen passwords or repeated prompts.
  • Push-Based Authentication: Push-based authentication sends a login approval request to a registered device instead of transmitting a reusable code. The user approves or denies the attempt on the device itself, often with added context such as location or device posture. This reduces exposure to SMS interception and improves phishing resistance.
  • Credential Blast Radius: Credential blast radius is the amount of access, data, and system reach that a single compromised secret can unlock. The wider the blast radius, the more damage one leaked token or certificate can cause. Reducing it requires tighter scope, faster revocation, and better segmentation.

Deepen your knowledge

NHI governance, human identity, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org