Skip to content

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.

Glossary

MFA fatigue (push bombing)

An attack in which someone who has the password sends repeated MFA push prompts until the user approves one, tracked by MITRE ATT&CK as T1621.

MFA fatigue, also called push bombing, is an attack where an adversary who already has a user's password triggers sign-in after sign-in so the user receives a stream of push notifications, hoping one gets approved out of fatigue, confusion or a convincing phone call. MITRE ATT&CK tracks it as T1621, Multi-Factor Authentication Request Generation.

In Okta it appears as bursts of system.push.send_factor_verify_push, with rejections as user.mfa.okta_verify.deny_push (Classic Engine) or failed user.authentication.auth_via_mfa (Identity Engine). Number challenge and phishing-resistant MFA are the main defences. See MFA fatigue detection.

This tool is not affiliated with, endorsed by or sponsored by Okta, Inc. Okta is a trademark of Okta, Inc. Other names are trademarks of their respective owners.