Identity & Access
MFA Fatigue & Bypass
Modern attacks bypass or exhaust MFA rather than crack passwords.
What it is
MFA fatigue (push bombing) floods a user with authentication requests until they approve one out of frustration or confusion. Adversary-in-the-Middle (AiTM) phishing kits proxy real authentication sessions in real time, capturing session cookies after MFA is completed. SIM swapping hijacks SMS-based MFA by porting the victim's phone number to an attacker-controlled SIM. Passkey-resistant phishing pages that capture FIDO2 session tokens are an emerging variant in 2025.
Attack techniques
- MFA Push Bombing (T1621)
- AiTM Phishing (T1557.002)
- SIM Swapping (T1078)
- Pass-the-Cookie (T1550.004)
- Bypass via legacy auth protocols (T1078.004)
Business impact
Even organisations with MFA enforced are vulnerable. A bypassed MFA session gives attacker-controlled access that appears fully legitimate, with no password compromise involved.