Call NowFree Quote
Cybersecurity

MFA Fatigue & Push-Bombing Attacks Explained

MFA closes the door on most account takeover attempts, so attackers have found a way around it that doesn't touch the technology at all, it targets the person approving the prompt. Push-bombing has been behind several high-profile breaches overseas, and it works just as well against a Perth business as a global enterprise.

How Push-Bombing Actually Works

An attacker who already has a valid username and password (from a data breach, a phishing page, or reused credentials found on the dark web) triggers a login attempt over and over. Each attempt sends a genuine push notification to the real user's phone asking them to approve or deny the sign-in. Sent once, most people deny it correctly. Sent fifteen times at midnight, plenty of people eventually tap approve just to make it stop, especially if a follow-up message pretends to be IT asking them to confirm.

Why It Works Even on Security-Aware Staff

This isn't a technical failure, MFA is functioning exactly as designed, the attacker just moved the attack from the system to the person. Notification fatigue, ambiguity about what a legitimate prompt looks like, and a plausible "IT support" follow-up message all combine to make a single mistaken tap likely given enough attempts. It's the same underlying weakness as social engineering more broadly, exploiting human response to pressure rather than a system flaw.

The Fix: Number Matching

Most modern MFA apps, including Microsoft Authenticator, support number matching, the user must type a number shown on the sign-in screen into the app rather than tapping a single approve button. This single setting defeats push-bombing almost entirely, because a blind approval no longer works, the attacker would need the number from the real screen too. If your business hasn't confirmed this is switched on, it's a five-minute check worth doing today.

Beyond Number Matching

  • Cap the notification rate - configure sign-in throttling so repeated failed attempts lock the account rather than allowing unlimited prompts.
  • Move toward phishing-resistant MFA - passkeys remove the approve/deny prompt entirely for high-value accounts.
  • Tell staff what to do - report repeated, unexpected prompts to IT immediately rather than dismissing them, and never approve a prompt they didn't initiate.
  • Review sign-in logs - a burst of denied MFA attempts is a strong signal a password has already been compromised, worth investigating even if every prompt was correctly denied.

Frequently Asked Questions

Does this mean MFA doesn't work?

No, MFA still stops the overwhelming majority of account takeover attempts. Push-bombing only works against push-notification MFA specifically, and only once an attacker already has a valid password to trigger the prompt in the first place.

Is SMS MFA safer than push notifications for this reason?

Not really, SMS carries its own weaknesses like SIM swapping and is generally considered the weakest MFA option overall. The better fix is number matching or phishing-resistant methods, not falling back to SMS.

How would we even know if this happened to us?

A spike of MFA denial notifications a staff member didn't expect is the clearest sign, which is why it's worth telling staff explicitly to report repeated prompts rather than just dismissing them as an app glitch.

Is this worth worrying about for a small business, or just larger targets?

It's worth a five-minute fix (enabling number matching) regardless of size. The attack only requires a leaked password, which is a low bar, and the accounts targeted are usually whichever ones have the most useful access, not necessarily the biggest company.

We can check your MFA configuration and turn on number matching in one visit.

Cybersecurity Services →

Not sure what your MFA setup actually allows?

Call 0433 087 091 for a free, no-obligation IT health check.

Book a Free IT Health Check

For related reading, see MFA Setup for Perth Businesses, Passkeys and Phishing-Resistant MFA, and Dark Web Monitoring for Perth Businesses.

Share this article