Join our Newsletter — 33% off our NHI Course

Mfa fatigue attacks: are push prompts still safe enough?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: MFA fatigue attacks flood users with push notifications until one is approved, according to Axiad, and a report from Expel found that 80% of successful business account compromise attacks occurred on accounts already protected by MFA. Push-based MFA is only as strong as the user's ability to resist manipulation.

Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “The Growing Problem with MFA Fatigue Attacks (And What You Can Do About It)”.

By the numbers:

  • 80% of successful business account compromise attacks occurred on accounts already protected by MFA, according to Expel research cited by Axiad.

Key questions

Q: What breaks when push-based MFA is exposed to repeated notification attacks?

A: The control breaks when approval becomes automatic instead of deliberate.

Q: Why do push notifications make account takeover easier for attackers?

A: Push notifications make account takeover easier because they turn authentication into a repeated decision point that an attacker can manipulate.

Q: What are the signs that MFA fatigue is being used against users?

A: Common signs include a burst of push requests, approvals that happen after several denials, unexpected enrolment of a new device, and suspicious sign-ins that align with user distraction or help desk impersonation.

Practitioner guidance

  • Require phishing-resistant authenticators Prioritise public key based and passwordless methods for users who access sensitive systems, especially where push approval is currently the default factor.
  • Limit repeated MFA attempts Set thresholds that flag or block unusual volumes of MFA requests, because repetitive prompts are a core abuse pattern in fatigue attacks.
  • Constrain MFA method choice Restrict weaker methods such as SMS or email codes where stronger options are available, and remove fallback paths that attackers can steer users toward.

Bottom line: MFA fatigue attacks succeed by exploiting the human approval step, which means the weakness is the control design rather than the existence of MFA itself.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Push fatigue is a governance failure in the authentication decision, not merely a user mistake. Repeated approval prompts turn the human into the weakest control point in the trust chain. When authentication can be worn down through repetition, the programme is assuming users will behave like deterministic policy engines, which they do not. The practitioner conclusion is that approval-based MFA cannot be treated as a sufficient control on its own.

A few things that frame the scale:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

A question worth separating out:

Q: How should organisations reduce MFA-related account takeover risk?

A: Start by replacing the weakest factors on the highest-risk accounts, then remove recovery paths that depend on shared secrets or easily intercepted delivery channels. Pair that with risk-based step-up, strong offboarding, and continuous review of fallback access. The goal is to make takeover harder without turning authentication into a usability failure.

👉 Read our full editorial: Mfa fatigue attacks expose the limits of push-based authentication


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.