Cybersecurity definition
What is MFA Fatigue?
By Cyber Tool Stack Editorial TeamUpdated
Definition
An attack where someone who already has a victim's password sends a flood of push-based MFA approval requests, hoping the victim eventually taps 'approve' just to make the notifications stop — also called MFA bombing or push bombing.
Where MFA Fatigue fits in the security landscape
These beginner lessons use this term while explaining the surrounding security control.
Related cybersecurity terms
MFAMulti-Factor AuthenticationA login flow that requires a second proof of identity beyond a password, such as a push approval, one-time code, or biometric check, so a stolen password alone isn't enough to log in.VishingPhishing carried out over a phone call, often impersonating IT support, a bank, or an executive to pressure the victim into revealing credentials, approving an MFA prompt, or transferring money.