Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is multi-factor authentication fatigue?

Multi-factor authentication fatigue uses repeated authentication prompts to pressure, confuse or wear down a user until one is approved.

It often happens after the attacker already has the password and needs the second factor to complete access.

Reconstruct the prompt sequence

A useful provider history might show:

Example MFA prompt sequence
14:01 · MFA prompt denied14:03 · MFA prompt ignored14:05 · MFA prompt denied14:07 · phone call received from “IT support”14:09 · MFA prompt approved14:09 · new session S-7719 created

The sequence matters more than the final approval on its own.

A user may approve because:

  • they think the prompt belongs to their own login;
  • somebody impersonating support tells them to;
  • repeated prompts become confusing;
  • they approve accidentally;
  • the interface gives little context.

Record what the prompt showed and what the user understood.

Rule out legitimate repeated prompts

Misconfigured applications, stale sessions or genuine retries can also create multiple MFA challenges.

Compare:

  • source infrastructure;
  • application/client;
  • timing;
  • account activity;
  • calls/messages;
  • session created after approval.
Repeated promptsChallenge pressureDenied, ignored or repeated requests.
Social contactVictim is influencedCall or message may explain the approval.
ApprovalSecond factor succeedsProvider records the event.
SessionAccess followsAccount activity shows consequence.

Containment may need more than a password reset

If a session or refresh token was created, access may persist until that route is revoked.

The practical point is: interpret an MFA approval through the prompts, social contact and session that surround it. The approval proves the factor succeeded, not that the user knowingly authorised the attacker.

Reference: CIM-056Cyber Incidents & Offender Methods