T1621 Multi-Factor Authentication Request Generation — Detection & Response
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. MFA Request Generation may be used in tandem with Valid Accounts (T1078). To generate MFA push requests, adversaries may need the target's username and password.
Coverage at a glance
- Detections shipped
- 4
- Avg. verdict time
- < 5 min
- Data sources
- 2+
Threat context
How adversaries use T1621 Multi-Factor Authentication Request Generation — Detection & Response
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. MFA Request Generation may be used in tandem with Valid Accounts (T1078). To generate MFA push requests, adversaries may need the target's username and password.
MFA fatigue (also called MFA bombing) is among the most operationally simple yet effective techniques in the modern attacker playbook. The attacker obtains valid credentials (via phishing, credential stuffing, or purchase) and then repeatedly triggers MFA push notifications to the target's device. After receiving dozens of pushes, users often approve one to stop the notifications, or the attacker combines the push flood with a phone call claiming to be IT support requesting approval. This technique bypassed MFA at Uber, Cisco, and Microsoft's own email systems.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| MFA Push Flood — User receives 5+ push requests in 10 minutes A user receives an abnormally high number of MFA push requests in a short window, consistent with a fatigue attack in progress. | Critical | Okta / Duo |
| MFA Approval After Multiple Denials — Push approved after several recent denials A user denied multiple MFA pushes but then approved one — high-confidence indicator of fatigue compromise. | Critical | Okta / Duo |
| MFA Approval from New Country — First-time approval from geographically new location MFA was approved but the authenticating device is located in a country where the user has never previously authenticated. | High | Okta / Entra ID |
| Rapid MFA Failures Across Multiple Users — Multiple users receiving pushes from same source Multiple users receive MFA requests within a short time window, indicating a coordinated MFA fatigue campaign. | High | Okta / Duo |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1539 Steal Web Session Cookie — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response: frequently asked questions
What is the difference between MFA fatigue and other MFA bypass techniques?
MFA fatigue exploits user behaviour — the attacker has the correct password and triggers legitimate MFA requests. AiTM phishing (T1557) captures the session cookie after successful MFA to avoid the MFA step entirely. Passkeys/FIDO2 defeat both: they are phishing-resistant and cannot be remotely pushed.
Does ManySignal auto-suspend a user during an active MFA fatigue attack?
Yes, when configured. ManySignal's response policy can automatically suspend an account or revoke sessions when the MFA push flood pattern is detected with high confidence, pending analyst review within a configurable window.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.