← Back to glossary

Attack technique abusing repeated MFA push prompts to induce user acceptance; often paired with social engineering.

Definition

MFA fatigue targets push MFA by generating repeated prompts. Defenses include number matching, rate limits, and phishing-resistant MFA (passkeys/security keys).

In plain English Attack technique abusing repeated MFA push prompts to induce user acceptance; often paired with social engineering.

Why this matters

Why it matters: Turns human error into an MFA bypass path.

Example

Example: Require number-matching approvals, block repeated prompts, and migrate high-risk users to passkeys.