Open cardosec

Case 9462ED · Identity & AD · L1 Foundations

MFA Fatigue

Practise as: Explain it · Interview

Interview questionUsers have MFA, yet an attacker still got in by spamming push prompts. What failed and what do you change?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Attacker already has the password and floods push approvals until a tired or confused user taps Approve
  2. Often paired with a call or message pretending to be IT support; used in the 2022 Uber breach
  3. Fix: number matching and showing app/location context in the prompt; rate-limit and alert on repeated denials
  4. Stronger: phishing-resistant MFA (FIDO2/passkeys, smart cards) which binds auth to the real site origin
  5. Train users that an unexpected prompt means their password is compromised and should be reported

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.