Offcanvas Logo

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

Menu

  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us

Contact Us

  • 1 Executive Dr Suite 100 #123 Marlton NJ 08053
  • 856-282-4100
  • info@xitx.com

info@xitx.com
856-282-4100
1 Executive Drive Suite 100 Marlton, NJ 08053
+1 856-282-4100
Facebook-f X-twitter Instagram Linkedin-in Youtube
Xact IT Solutions
Let’s Talk
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Xact IT Solutions
  • IT Support
  • Cybersecurity
  • IT Compliance
  • AI Services
  • Blog
  • Why Us
Let’s Talk

MFA Fatigue Attacks: Why Multifactor Authentication Alone Won’t Keep Attackers Out

Multifactor authentication was supposed to close the door. Add a second factor to your logins and you’re dramatically safer – that was the promise, and it was a true one. Then attackers spent three years figuring out how to get someone to open the door from the inside. What the 2024 and 2025 breach disclosures make clear is that telling your team “we turned on multifactor authentication, you’re covered” is no longer enough. The gap between having it and having the right configuration is exactly where the attacks are happening now.

  1. What Is an MFA Fatigue Attack?
  2. What the FBI IC3 and CISA Data Actually Say
  3. Real Breach Examples: 2023 – 2025
  4. Who Is Most at Risk Among Small and Mid-Sized Businesses?
  5. Why Basic Push-Based MFA Fails Against MFA Fatigue Attacks
  6. A Realistic Defense Posture
  7. What to Ask Your IT Firm Right Now

What Is an MFA Fatigue Attack?

The mechanics are straightforward, which is part of what makes this technique so effective. A threat actor obtains a target’s username and password – usually from a prior data breach, a credential-stuffing campaign, or a phishing email. With those credentials in hand, they attempt to log in repeatedly. Each attempt triggers a push notification to the legitimate user’s phone asking them to approve the sign-in.

The attacker keeps sending requests – dozens of them, sometimes in the middle of the night. The goal is not technical sophistication. It is exhaustion, confusion, or one distracted moment. The target eventually approves a request to make the notifications stop, assuming it is a system glitch. At that moment, the attacker is inside the account.

This technique is also called push bombing or push notification abuse. CISA formally documented it in its guidance on implementing number matching in multifactor authentication applications – specifically because MFA fatigue attacks had become widespread enough to warrant federal advisory-level attention.

What the FBI IC3 and CISA Data Actually Say About MFA Fatigue Attacks

MFA fatigue attacks - Wide shot of a person at a desk in a dimly lit office at night, head in hand looking exhausted while their computer monitor glows in the background, conveying fatigue and decision-making under pressure.

The FBI’s Internet Crime Complaint Center reported $12.5 billion in losses from cybercrime in 2023 – a record at the time – with business email compromise and account takeover fraud accounting for the largest share of financial damage. The 2024 IC3 report, released in spring 2025, showed continued growth in credential-based intrusions as the dominant entry point for financially motivated attacks.

CISA’s 2024 advisory landscape reinforced the same pattern. In joint advisories with the NSA, FBI, and international partners, CISA repeatedly cited phishing and multifactor authentication bypass as the top two initial access techniques used by both nation-state actors and financially motivated criminal groups. The advisory tied to the Scattered Spider threat group – responsible for the MGM Resorts breach and a string of subsequent attacks – specifically called out push notification bombing as a core technique.

The 2025 Verizon Data Breach Investigations Report, which draws on thousands of confirmed breach incidents globally, found that credential abuse remained the number-one action type in breaches, with social engineering (including techniques that manipulate users into approving authentication requests) continuing to climb as a percentage of total incidents. These are not projections. They are confirmed breach records.

Real Breach Examples: 2023 – 2025

The highest-profile documented case remains the September 2023 MGM Resorts International breach. The attackers – attributed to Scattered Spider, a loosely affiliated group of English-speaking threat actors – used a combination of LinkedIn research, a 10-minute help desk call, and push notification fatigue to gain access to MGM’s identity infrastructure. The resulting disruption cost MGM an estimated $100 million in a single quarter, according to public SEC filings.

Caesars Entertainment disclosed a separate breach around the same period, reportedly paying approximately $15 million to ransomware operators after attackers used similar social engineering and authentication bypass techniques. Caesars disclosed the breach in an SEC filing under mandatory reporting rules that took effect in December 2023.

Beyond the headline cases, smaller incidents tell the same story at a scale that is directly relevant to businesses with 10 to 200 employees:

  • A 2024 CISA advisory on healthcare sector intrusions documented cases where attackers used stolen credentials plus push notification abuse to access patient records systems – bypassing multifactor authentication that had been implemented specifically to meet HIPAA security rule guidance.
  • Microsoft’s 2024 Digital Defense Report noted that its threat intelligence team observed hundreds of organizations targeted by MFA fatigue campaigns monthly, with small and mid-sized businesses increasingly in scope as larger enterprises hardened their controls.
  • A 2025 joint advisory from CISA, FBI, and the Australian Signals Directorate identified automated infrastructure being used to support credential harvesting campaigns that fed push notification attacks – indicating these attacks have become more scalable, not less.

The pattern across all of these cases is consistent: the attacker did not break the cryptography. The attacker broke the person.

Who Is Most at Risk Among Small and Mid-Sized Businesses?

Small businesses face a specific version of this risk that enterprise security architecture does not fully address. There are several reasons why.

First, small businesses are more likely to be running basic push-based multifactor authentication – the kind that sends a simple “Approve or Deny” notification – rather than more resistant methods like number matching or phishing-resistant hardware keys. That simpler setup was what IT vendors recommended three to five years ago, and most businesses have never revisited it.

Second, small business employees wear more hats. The person handling accounts payable, HR, and vendor management at a 20-person firm carries more cognitive load than a specialist at a large company. That cognitive load is precisely the condition that makes MFA fatigue attacks more likely to succeed – a distracted person is more likely to approve an unexpected notification just to clear the interruption.

Third, small businesses often lack the monitoring needed to detect an unusual volume of failed authentication attempts against a single account. Without that visibility, the attack may succeed before anyone notices the pattern.

Fourth, credential exposure is universal. If any employee’s email address and password combination has appeared in a public breach – and with billions of credentials circulating on criminal forums, statistically at least one has – the precondition for a push notification attack is already in place. You do not need to have been breached directly. You need only to have had credentials exposed anywhere, ever.

Why Basic Push-Based MFA Fails Against MFA Fatigue Attacks

It is worth being direct here, because the cybersecurity industry has not always been honest with small businesses about the limitations of what it sold them.

Standard push-based multifactor authentication – the kind built into Microsoft 365, Google Workspace, and most cloud platforms by default – asks the user to approve or deny a login attempt. It does not, by default, show the user where the login attempt is coming from, what IP address initiated it, or any contextual signal that would help distinguish a legitimate login from an attack. It asks a binary question under conditions where the user has no information with which to answer it accurately.

CISA’s number matching guidance addresses this directly. Number matching requires the user to enter a number displayed on the sign-in screen into their authentication app, rather than simply tapping Approve. This defeats push bombing because the attacker cannot provide the correct number to the target. Microsoft implemented number matching as a default in Microsoft Authenticator in 2023 – but only for organizations that updated their configuration. Many have not.

Beyond number matching, phishing-resistant authentication methods – specifically FIDO2-compliant hardware security keys or passkeys – are the only authentication types CISA currently classifies as resistant to both phishing and MFA fatigue attacks. These methods cryptographically bind authentication to the legitimate site or application, so a stolen password provides no value to an attacker at all. NIST’s Digital Identity Guidelines (SP 800-63) classify these as the highest-assurance authentication methods available.

The gap between “we have multifactor authentication” and “we have multifactor authentication that is resistant to the attacks currently being used against us” is significant. For many small businesses, that gap is the primary open door.

How MFA fatigue attacks work: attackers flood users with push notifications until one is accidentally approved.

A Realistic Defense Posture Against MFA Fatigue Attacks

Closing that gap does not require a large budget or a team of security engineers. It requires knowing what you have, understanding where it falls short, and making deliberate decisions about which controls to upgrade first. Here is what a grounded defense posture looks like against this specific threat.

Audit your current authentication methods. For every application that holds sensitive data or financial access, confirm what type of multifactor authentication is in use. If it is a simple Approve/Deny push, it is worth upgrading.

Enable number matching everywhere it is available. In Microsoft 365, this is a configuration change in the Entra ID (formerly Azure AD) authentication methods policy. It takes roughly 15 minutes to configure and eliminates the core vulnerability in push bombing attacks. Google Workspace has equivalent controls. If your IT firm has not done this, ask why not.

Move your highest-value accounts to phishing-resistant authentication. Finance, executive, IT administrator, and HR accounts carry the most risk. Hardware security keys or platform passkeys for those accounts represent a meaningful upgrade in protection at relatively low cost.

Implement authentication anomaly alerting. A burst of denied multifactor authentication requests against a single account at 2 a.m. is a signal that an MFA fatigue attack is in progress. That signal is only useful if someone is watching for it. Automated alerting tied to your identity platform’s sign-in logs can catch a push bombing attempt before a tired employee approves the wrong notification.

Train employees on what a legitimate authentication request looks like. Your organization should have a clear policy: if you receive an authentication request you did not initiate, deny it immediately and report it. That policy is worthless if employees do not know it exists. A short, specific training message – not a generic annual compliance module – is more effective than a checkbox exercise.

Audit for exposed credentials proactively. Services like Have I Been Pwned, or the dark web monitoring capabilities built into many identity platforms, can identify which employee email addresses have appeared in public breach data. Knowing a credential is exposed before an attacker uses it is a significant advantage. A well-configured environment can surface these alerts automatically.

Together, these controls do not eliminate all risk – no set of controls does. But they close the specific vulnerability that MFA fatigue attacks exploit: the gap between “we have multifactor authentication” and “we have multifactor authentication that works against the attacks being used right now.”

The organizations that do not make the breach report are the ones that have invested in a layered approach – not just multifactor authentication, but identity monitoring, anomaly detection, and credential hygiene working together. That kind of quiet is the goal. See how Xact IT approaches cybersecurity for small and mid-sized businesses – and why zero client breaches in 22 years of operation is not an accident. You can also review our managed IT services to see how proactive monitoring fits into a complete security program.

What to Ask Your IT Firm Right Now

If you have a managed IT or cybersecurity provider, this post should prompt a direct conversation. Here are the specific questions worth asking.

  • What type of multifactor authentication are we using on Microsoft 365, Google Workspace, and other cloud accounts – and is number matching enabled?
  • Do we have any accounts still using simple push approval without number matching or additional context?
  • Are our administrator and finance accounts using phishing-resistant authentication methods, such as hardware keys or passkeys?
  • Do we have alerting in place for unusual authentication activity, including repeated failed multifactor authentication attempts against a single account?
  • Have any employee email addresses appeared in public credential breach databases, and how are we monitoring for that going forward?
  • When did we last review and update our authentication policies – and does our current configuration reflect CISA’s guidance on number matching and phishing-resistant methods?

A competent IT firm should answer every one of those questions concisely and specifically. Vague reassurances – “yes, we have multifactor authentication enabled” – are not sufficient. The data from 2024 and 2025 confirms that the presence of multifactor authentication is no longer the meaningful security checkpoint it was five years ago. The relevant question is which type, configured how, with what monitoring behind it.

The threat actors running MFA fatigue attacks are not particularly sophisticated. They are patient, they are systematic, and they are counting on the gap between what small businesses were told about multifactor authentication and what it actually does under current attack conditions. Closing that gap is a specific, achievable project – not a years-long security overhaul. The businesses that do it quietly are the ones that do not become a case study in next year’s IC3 report.

Frustrated With Your Current IT Provider?

If your current MSP isn’t catching the things this post describes, that’s a signal worth acting on. Book a strategy call and we’ll walk through what an honest IT partnership looks like for a business your size.

Claim Your Free Strategy Call

Recent Posts

  • Cybersecurity Personal Accountability: Protecting Executive Assets from Rising Legal Liability
  • How Neglected Office Hardware Becomes an Open Door for State-Sponsored Hackers
  • Stop Creating Digital Dust: How to Make AI Writing Tools for Internal Documentation Actually Work
  • Supply Chain Cyber Attacks: How to Secure Your Logistics Networks
  • How Subdomain Takeover Phishing Exploits Abandoned Domain Records

Categories

  • AI for Business
  • Backup & Recovery
  • Blog
  • Business
  • Buyer Guides
  • CMMC
  • Compliance
  • Cybersecurity
  • Healthcare
  • Managed IT
  • News & Analysis
  • Threat Intelligence

Share

FRUSTRATED WITH YOUR CURRENT IT PROVIDER? LET’S TALK.

Get a Free IT Consultation
Xact IT Solutions
  • info@xitx.com
  • +1 856-282-4100
  • 1 Executive Drive Suite 100 Marlton NJ 08053

Follow Us

Quick Links
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Book Your Strategy Call
Services
  • IT Support
  • Cybersecurity Services for SMBs | Xact IT Solutions
  • IT Compliance
Recent Blogs
  • Supply-Chain Ransomware Attack Impacts 60 Credit Unions
  • Comcast Xfinity Data Breach Exposes 36 Million Customers’ Data
  • Crown Equipment’s Cyberattack: Recovery and Lessons Learned
Copyright © 2026. Website Design by Xact IT Solutions
  • Privacy Policy and Terms & Conditions
  • Home
  • Partner Program
  • Why Choose Xact IT Solutions | Xact IT Solutions
  • Book Your Strategy Call