What is multi-factor authentication fatigue?¶
Multi-factor authentication fatigue uses repeated authentication prompts to pressure, confuse or wear down a user until one is approved.
It often happens after the attacker already has the password and needs the second factor to complete access.
Reconstruct the prompt sequence¶
A useful provider history might show:
S-7719 createdThe sequence matters more than the final approval on its own.
Approval is not the same as informed consent¶
A user may approve because:
- they think the prompt belongs to their own login;
- somebody impersonating support tells them to;
- repeated prompts become confusing;
- they approve accidentally;
- the interface gives little context.
Record what the prompt showed and what the user understood.
Rule out legitimate repeated prompts¶
Misconfigured applications, stale sessions or genuine retries can also create multiple MFA challenges.
Compare:
- source infrastructure;
- application/client;
- timing;
- account activity;
- calls/messages;
- session created after approval.
Containment may need more than a password reset¶
If a session or refresh token was created, access may persist until that route is revoked.
The practical point is: interpret an MFA approval through the prompts, social contact and session that surround it. The approval proves the factor succeeded, not that the user knowingly authorised the attacker.