MFA fatigue (push bombing)
An attack in which someone holding a stolen password triggers repeated MFA push prompts until the user approves one, often out of annoyance or after a fake support call.
MFA fatigue, also called push bombing, targets multi-factor authentication that asks the user only to approve or deny a sign-in on their phone. An attacker who already has the password, for example from credential stuffing, starts repeated sign-ins, and each sends a push prompt. The user may approve one to stop the noise, by mistake, or because the attacker phones them posing as the help desk and asks them to. The phrase “two-factor authentication (2FA) fatigue”, which the ISC2 exam outline uses under security training and awareness (7.15), refers to the same attack.
NIST SP 800-63B-4 names this “authentication fatigue” in its section on out-of-band devices. It requires the out-of-band secret to be transferred between the login screen and the device, such as a number the user must enter, so the user has to take part in the specific session, and it says that asking the user only to compare codes and approve is no longer acceptable because of these attacks. It adds that a verifier sending push notifications should limit how many it sends. Phishing-resistant authentication, such as FIDO2 security keys or passkeys, removes the approval prompt as a route in.
Exam relevance: a scenario is likely to describe a user flooded with sign-in prompts who eventually taps approve. Candidates are expected to name MFA fatigue, and to prefer number matching or phishing-resistant authenticators over simply retraining users or removing MFA.