Case 9462ED · Identity & AD · L1 Foundations
MFA Fatigue
Practise as: Explain it · Interview
Interview questionUsers have MFA, yet an attacker still got in by spamming push prompts. What failed and what do you change?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Attacker already has the password and floods push approvals until a tired or confused user taps Approve
- Often paired with a call or message pretending to be IT support; used in the 2022 Uber breach
- Fix: number matching and showing app/location context in the prompt; rate-limit and alert on repeated denials
- Stronger: phishing-resistant MFA (FIDO2/passkeys, smart cards) which binds auth to the real site origin
- Train users that an unexpected prompt means their password is compromised and should be reported
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.