Identity & Access

MFA Fatigue & Bypass

Modern attacks bypass or exhaust MFA rather than crack passwords.

What it is

MFA fatigue (push bombing) floods a user with authentication requests until they approve one out of frustration or confusion. Adversary-in-the-Middle (AiTM) phishing kits proxy real authentication sessions in real time, capturing session cookies after MFA is completed. SIM swapping hijacks SMS-based MFA by porting the victim's phone number to an attacker-controlled SIM. Passkey-resistant phishing pages that capture FIDO2 session tokens are an emerging variant in 2025.

Attack techniques

  • MFA Push Bombing (T1621)
  • AiTM Phishing (T1557.002)
  • SIM Swapping (T1078)
  • Pass-the-Cookie (T1550.004)
  • Bypass via legacy auth protocols (T1078.004)

Business impact

Even organisations with MFA enforced are vulnerable. A bypassed MFA session gives attacker-controlled access that appears fully legitimate, with no password compromise involved.