Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response What should organisations do when attackers are trying…
Threats, Abuse & Incident Response

What should organisations do when attackers are trying to abuse push notification fatigue for MFA bypass?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Threats, Abuse & Incident Response

Organisations should disable or tightly limit approval-based MFA where possible, because repeated prompts can wear users down until they approve a malicious request. Combine number matching or phishing resistant methods with alerting on multiple denied or unanswered prompts, and add user education about prompt bombing. The goal is to make a single accidental approval insufficient for access.

What the control needs to accomplish

push notification fatigue becomes dangerous when the attacker’s real objective is not the first prompt, but the one a user approves after repeated interruptions. A good response is to remove the attacker’s leverage by reducing approval-based prompts, then hardening the approval path with phishing-resistant methods, number matching, and monitoring for repeated denial or timeout patterns.

Where approval prompts are still allowed, treat them as a high-friction fallback rather than a routine login path. Repeated prompts should be an observable signal, not just a user inconvenience, because prompt bombing only works when the environment lets attackers keep pressing the same weak approval surface.

Why prompt bombing works in practice

Attackers abuse fatigue because it exploits human attention, not cryptographic weakness. If the organisation relies on a single tap or approve button, the control can fail even when the attacker never learns the password, because a moment of distraction, confusion, or annoyance is enough to complete authentication.

This is why stronger methods matter. Number matching adds a check that is harder to approve blindly, while phishing-resistant methods such as passkeys or hardware-backed authenticators remove the attacker’s ability to win by repeatedly sending the same request. A useful internal reference is NHIMG’s Uber Breach, which illustrates how mfa fatigue can be operationalised by an attacker.

For a broader pattern of abuse across identity material, NHIMG’s 52 NHI Breaches Analysis shows how compromised access paths often become persistent once an attacker finds a weak approval or token path. The same operational lesson applies here: the first mistake is rarely the only control failure.

What practitioners should change first

The first priority is to identify every approval-based MFA path that can be spammed, then decide whether it can be disabled, restricted, or replaced. Systems that support conditional access, device-bound authenticators, or phishing-resistant MFA should be moved ahead of legacy push approval flows, especially for privileged accounts and remote access.

What to verify: confirm that repeated unanswered or denied prompts are being logged, alerted on, and reviewed quickly enough to stop an attacker while the campaign is still in progress. If the security team cannot see prompt volume, denial streaks, or unusual geographic and device patterns, the organisation is relying on user behaviour alone.

Common mistake: treating MFA fatigue as a user-training problem only. Training helps, but it does not compensate for a design that still allows an attacker to submit unlimited prompts until someone makes a mistake.

For control mapping, this aligns with CISA cyber threat advisories, which consistently emphasise identity abuse and defensive monitoring, and with the NIST Cybersecurity Framework 2.0, especially its protect and detect functions.

Risk and Threat Considerations

push fatigue is a low-cost attack path because it turns an otherwise strong second factor into a repeated nuisance event. Once users begin to normalise unexpected prompts, the organisation may see a login as “failed” when it is actually under active pressure, which creates a short window for account takeover.

Failure mechanism: the attacker sends repeated authentication prompts until the target approves one request out of annoyance, confusion, or distraction, then immediately uses the authenticated session to access email, cloud apps, or internal systems.

Impact: a single accidental approval can grant durable access, enable mailbox or session takeover, and give the attacker a trusted starting point for lateral movement, token theft, or data exfiltration.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-7 — Identity Management, Authentication, and Access ControlFatigue-bypass MFA is an identity and access control weakness.
DE.CM-1 — Monitoring for Suspicious ActivityRepeated denied or unanswered prompts are suspicious identity activity.
Recommendation — Use phishing-resistant MFA and tighten access control for approval-based sign-ins. Alert on prompt spikes, denial streaks, and anomalous authentication attempts.
CIS Controls v86 — Access Control ManagementThe issue is insecure approval-based access control and excessive exposure to login abuse.
8 — Audit Log ManagementPrompt bombing needs logging to detect repeated attempts and user response patterns.
Recommendation — Restrict approval-based MFA and enforce stronger authentication for sensitive access. Log and review repeated MFA prompts, denials, and unusual authentication sequences.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureZero Trust requires stronger verification than a single push approval.
Recommendation — Apply Zero Trust principles to require stronger, contextual verification for access.
NIST SP 800-635.2.9 — Out-of-Band Device Secrets and MessagesPush approvals are vulnerable when the out-of-band channel can be abused repeatedly.
Recommendation — Prefer phishing-resistant authenticators and limit weak out-of-band approval flows.
OWASP Non-Human Identity Top 10NHI-02 — Secrets and Credential ExposureRepeated prompt abuse often leads to broader identity compromise and credential exposure paths.
NHI-08 — Excessive PrivilegeIf a fatigued approval grants access, overprivilege magnifies the blast radius.
Recommendation — Reduce exposure from compromised authentication paths and rotate affected secrets quickly. Limit privileged access so a single mistaken approval cannot expose broad systems.

Practitioner Guidance

Decision rule: if a user can approve access without a second contextual check, treat that path as vulnerable to fatigue abuse and prioritise replacing it before expanding policy exceptions or adding more end-user reminders.

What to measure: track repeated prompt sequences, approval-to-denial ratios, and the time between the first suspicious prompt and account lock or step-up challenge. A rising pattern of unanswered prompts is an early warning that the control is being probed rather than used normally.

Practitioner takeaway: the goal is not just to stop one malicious prompt, but to make repeated prompts lose their value as an attack technique by tightening the control, increasing observability, and removing the ability to approve blindly.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org