Skip to content
REDMAW

SaaS & Identity

MFA Fatigue & Push Bombing

Repeated authentication prompts pressure a user into approving a request they did not initiate, turning an enabled MFA control into a human weakness.

RedMaw

Definition

Where a second factor is a simple approve-or-deny push, an attacker who already holds a valid password can request approval repeatedly until the user accepts, through confusion, irritation or the assumption that something is malfunctioning.

Why this is a design property, not a bug

Nothing is technically broken. The factor is enrolled, the prompt is delivered, and the user approves. The weakness is that a binary prompt carries no context about what is being approved, and repetition converts a security decision into an annoyance to be dismissed.

What reduces the exposure

  • Number matching or other context binding in the prompt
  • Throttling and lockout on repeated denied requests
  • Phishing-resistant factors for privileged identities
  • Conditional access on device, location or risk signals
  • Alerting on abnormal prompt volume
Where it leads
  1. Credential
  2. Repeated MFA Prompt
  3. User Approval
  4. Identity
  5. SaaS Data

Each hop validated by successful exploitation

Tags

  • mfa
  • identity
  • account takeover

Validation

How RedMaw validates this attack

Validation runs only inside authorized scope, with agreed exploitation limits.

  1. 01Establish which factors are enrolled per identity class
  2. 02Identify identities relying on context-free approval prompts
  3. 03Review throttling, lockout and alerting on repeated requests
  4. 04Report the configuration gap rather than pressuring a person

Stop assuming you are secure. Prove it.

Continuously test what an attacker can actually reach across your applications, SaaS identities, internal infrastructure and AI systems.