M ManySignal
T1621 MITRE ATT&CK

T1621 Multi-Factor Authentication Request Generation — Detection & Response

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. MFA Request Generation may be used in tandem with Valid Accounts (T1078). To generate MFA push requests, adversaries may need the target's username and password.

Coverage at a glance

Detections shipped
4
Avg. verdict time
< 5 min
Data sources
2+

Threat context

How adversaries use T1621 Multi-Factor Authentication Request Generation — Detection & Response

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. MFA Request Generation may be used in tandem with Valid Accounts (T1078). To generate MFA push requests, adversaries may need the target's username and password.

MFA fatigue (also called MFA bombing) is among the most operationally simple yet effective techniques in the modern attacker playbook. The attacker obtains valid credentials (via phishing, credential stuffing, or purchase) and then repeatedly triggers MFA push notifications to the target's device. After receiving dozens of pushes, users often approve one to stop the notifications, or the attacker combines the push flood with a phone call claiming to be IT support requesting approval. This technique bypassed MFA at Uber, Cisco, and Microsoft's own email systems.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

MFA Push Flood — User receives 5+ push requests in 10 minutes

A user receives an abnormally high number of MFA push requests in a short window, consistent with a fatigue attack in progress.

Critical Okta / Duo

MFA Approval After Multiple Denials — Push approved after several recent denials

A user denied multiple MFA pushes but then approved one — high-confidence indicator of fatigue compromise.

Critical Okta / Duo

MFA Approval from New Country — First-time approval from geographically new location

MFA was approved but the authenticating device is located in a country where the user has never previously authenticated.

High Okta / Entra ID

Rapid MFA Failures Across Multiple Users — Multiple users receiving pushes from same source

Multiple users receive MFA requests within a short time window, indicating a coordinated MFA fatigue campaign.

High Okta / Duo

T1621 Multi-Factor Authentication Request Generation — Detection & Response: frequently asked questions

What is the difference between MFA fatigue and other MFA bypass techniques?

MFA fatigue exploits user behaviour — the attacker has the correct password and triggers legitimate MFA requests. AiTM phishing (T1557) captures the session cookie after successful MFA to avoid the MFA step entirely. Passkeys/FIDO2 defeat both: they are phishing-resistant and cannot be remotely pushed.

Does ManySignal auto-suspend a user during an active MFA fatigue attack?

Yes, when configured. ManySignal's response policy can automatically suspend an account or revoke sessions when the MFA push flood pattern is detected with high confidence, pending analyst review within a configurable window.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.