← All posts
4 min read

MFA Fatigue Attacks: Why “Approve” Prompts Get You Breached

Push-approval MFA felt like an upgrade over codes — until attackers realised they could just ask, repeatedly. An MFA fatigue attack (also called push bombing) floods a user with approval prompts until, out of confusion or exhaustion, someone taps “approve”.

It has been behind several high-profile breaches, and it works because the defense relies on a human making the right call under pressure.

How the attack works

The attacker already has the password (phished or leaked). They trigger login after login, firing a push prompt each time. Late at night, mid-meeting, or after the tenth buzz, one “approve” ends it — and the attacker is in.

No malware, no exploit. Just a channel that lets anyone with the password knock on the door as often as they like.

Why stronger passwords and more prompts don’t fix it

The password was never the control here — the approval was, and approvals are coercible. Number-matching helps but adds friction and still depends on the user. The real fix is to remove the blind “approve” entirely.

Remove the approve button

CyberCyko’s passwordless MFA has no push to spam. Sign-in requires a biometric on the enrolled device to unlock a hardware key that signs a one-time challenge — there is nothing to approve, and the signature is bound to the real site and device.

An attacker with the password gets nothing, because there is no shared secret and no prompt to pressure. It is the same principle behind verifying every request rather than trusting a single approval.

Ready to see it in your environment?

Stop MFA fatigue attacks