Threat Intelligence

MFA Fatigue (Push Notification Bombing): Detection, Defence, and Mitigation

MFA Fatigue, also known as Push Notification Bombing, is an emerging threat that exploits the convenience of multi-factor authentication (MFA) systems. As organisations increasingly rely on MFA to sec

CyberZonic Intelligence31 March 20265 min read
MFA Fatigue (Push Notification Bombing)Credential AccessT1621High volume of MFA push notifications sent to a single user within a short periodMultiple failed MFA challenges followed by a single successful approval

MFA Fatigue, also known as Push Notification Bombing, is an emerging threat that exploits the convenience of multi-factor authentication (MFA) systems. As organisations increasingly rely on MFA to secure their environments, attackers have devised methods to overwhelm users with excessive authentication requests, leading to human error and potential credential access. Security teams must understand this threat to implement effective countermeasures and protect sensitive data.

Introduction — What is this threat and why should security teams care?

MFA Fatigue is a high-severity attack technique that falls under the broader tactic of Credential Access (T1621). It involves bombarding a target user with a high volume of MFA push notifications within a short period, exploiting the user’s tendency to approve a request out of frustration or confusion. This can lead to unauthorised access to accounts, especially when combined with other attack vectors such as credential stuffing or phishing. As cyber threats evolve, organisations must remain vigilant and proactive in their defence strategies.

How It Works — Technical breakdown of the attack technique

The attack typically begins with an adversary obtaining a user's credentials through various means, such as phishing or data breaches. Once they have the username and password, they initiate a series of authentication attempts. Here’s a breakdown of the process:

  1. Initial Credential Acquisition: Attackers use phishing emails or social engineering tactics to gain a user's credentials. These credentials can be obtained from previous data breaches or through direct attacks.

  2. Flooding the Target: With the valid credentials, attackers send a high volume of MFA push notifications to the user’s device. This is often done using automated scripts that can generate multiple requests in quick succession.

  3. Human Error Exploitation: Faced with an overwhelming number of notifications, users may mistakenly approve one of the requests, believing it to be legitimate. This is particularly effective if the user is in a hurry or distracted.

  4. Successful Authentication: Once the user inadvertently approves the request, the attacker gains access to the account, allowing them to exploit it further for data theft, lateral movement, or other malicious activities.

  5. Geographical Anomalies: Attackers may also attempt to authenticate from geographically impossible locations relative to the user’s normal behaviour, which can serve as an indicator of compromise if not properly monitored.

Detection — How to identify this threat in your environment

To effectively detect MFA Fatigue attacks, security teams should monitor for the following indicators:

  • High Volume of Push Notifications: Review logs for an unusual number of MFA push notifications sent to a single user within a short timeframe. This could indicate an ongoing attack.

  • Multiple Failed MFA Challenges: Look for patterns of multiple failed MFA attempts followed by a single successful approval. This can suggest that the user was overwhelmed and mistakenly approved a request.

  • Geographical Anomalies: Monitor authentication attempts from locations that are inconsistent with the user’s typical behaviour. For instance, if a user in London receives push notifications from an IP address in another country, it should raise an alert.

  • User Behaviour Analytics: Implement user behaviour analytics (UBA) tools that can identify deviations from normal authentication patterns, providing an additional layer of detection.

Mitigation — Specific defensive measures and configurations

To mitigate the risks associated with MFA Fatigue, organisations should consider the following measures:

  1. Migrate to Advanced MFA Methods: Transition from simple push notifications to more secure MFA methods, such as number matching or challenge-response MFA. These methods require users to verify the request by entering a code or responding to a challenge, reducing the risk of accidental approvals.

  2. Implement FIDO2 Hardware Tokens: For privileged accounts, use phishing-resistant hardware tokens that comply with FIDO2 standards. These tokens provide a higher level of security and are less susceptible to social engineering attacks.

  3. Configure MFA Rate Limiting: Set up rate limiting on MFA requests to block excessive push notifications sent to a single user within a defined time frame. This can help prevent attackers from overwhelming users with requests.

  4. User Education and Awareness: Conduct regular training sessions to educate users about the risks of MFA Fatigue and the importance of scrutinising authentication requests. Encourage users to report suspicious activity immediately.

Recommended Actions — Step-by-step response plan for security teams

  1. Immediate Investigation: Upon detecting a high volume of MFA requests or unusual authentication patterns, initiate an investigation to determine if an attack is in progress.

  2. User Notification: Inform the affected user(s) about the potential attack and advise them to refrain from approving any MFA requests until the situation is resolved.

  3. Review Logs: Analyse authentication logs to identify the source of the requests and any geographical anomalies. Document your findings for further analysis.

  4. Implement Rate Limiting: If not already in place, configure MFA rate limiting to prevent further bombardment of push notifications.

  5. Enhance MFA Security: Evaluate the current MFA methods in use and consider migrating to more secure options, such as number matching or hardware tokens.

  6. Conduct a Post-Incident Review: After the situation is resolved, conduct a thorough review to identify any weaknesses in your current MFA implementation and update your security policies accordingly.

  7. Continuous Monitoring: Establish ongoing monitoring for MFA patterns and anomalies to detect potential future attacks early.

By understanding the mechanics of MFA Fatigue and implementing robust detection and mitigation strategies, organisations can significantly reduce their vulnerability to this high-severity threat.

For tailored cybersecurity solutions and expert guidance, contact CyberZonic today to fortify your organisation against evolving cyber threats.

Leave a Comment