Skip to main content
AAktoh Cyber
← Threat library

business

MFA fatigue (push bombing)

The attacker already has the password. They just spam approval prompts at 2am until someone taps 'Yes' to make it stop.

How it works

  1. 01Credentials are harvested from a breach dump or an infostealer log.
  2. 02The attacker triggers repeated push notifications, often overnight.
  3. 03Sometimes they call, posing as IT, to 'help you clear the prompts'.
  4. 04One accidental approval hands over a fully authenticated session.

How to spot it

  • Unexpected push prompts are a breach in progress, not a glitch — report, never approve.
  • Number matching and per-app conditional access remove most of the attack surface.
  • Repeated failed logins from a new ASN are the giveaway in the logs.

How the fleet stops it

Cerberus

Cerberus correlates identity provider telemetry with device posture and flags prompt storms within seconds. Argus tells you whether the password came from a known breach so you fix the root cause, not just the symptom.