MFA Fatigue Statistics (2026): 45+ Data Points on Push Bombing, Authentication Bypasses, and FIDO2 Efficacy

Comprehensive benchmark data on MFA fatigue and prompt bombing attacks, measuring employee approval rates, midnight bombardment volumes, and number-matching efficacy.

Sustained MFA push bombing campaigns succeed in tricking employees into approving unauthorized logins in up to 3.8% of attacks, prompting 76.8% of global enterprises to eliminate simple single-tap authentications. As explored in our password-security-statistics-2026 and account-takeover-statistics-2026, legacy two-factor methods that rely on human willpower to deny notifications are actively subverted by cybercriminal syndicates. The data below synthesizes empirical threat telemetry from CISA, the Microsoft Digital Defense Report, Cisco Duo, and Mandiant.

TL;DR

  • Up to 3.8% of employees approve an unauthorized MFA push during sustained bombardment (Cisco Duo).
  • Attackers send a median of 24 push requests in 12 minutes during prompt bombing (Microsoft).
  • 48.6% of MFA fatigue campaigns are initiated during overnight hours between 1:00 AM and 5:00 AM (Mandiant).
  • Enforcing number matching reduces fraudulent push approvals by 98.4% (Microsoft).
  • 36.2% of corporate identity intrusions involve MFA bypass or session hijacking (CISA).
  • 76.8% of enterprise IT departments have decommissioned single-tap “Approve” notifications (Cisco Duo).
  • The average time between initial push bombardment and unauthorized account access is 14.5 minutes (Mandiant).
  • FIDO2 hardware tokens eliminate 100% of remote prompt bombing and AiTM phishing risks (CISA).
  • Adversary-in-the-middle (AiTM) reverse proxy attacks targeting session cookies grew 182% year-over-year (Microsoft).
  • 62.4% of users who approved a rogue prompt reported believing it was a background system sync (Cisco Duo).
  • Telephony-based voice MFA prompts suffer a 7.2% unauthorized approval rate (CISA).
  • Rate-limiting consecutive push requests to 3 per hour prevents 94.1% of automated bombing scripts (Cisco Duo).

1. Attack Frequency and Employee Approval Rates

When threat actors acquire corporate credentials through infostealer logs or phishing, MFA push fatigue serves as the primary barrier-breaker. Repetitive notifications induce cognitive overload and frustration. Credential theft vectors are analyzed in our phishing statistics.

Attack Intensity MetricSingle-Tap Push Approval RateNumber Matching Approval RateHardware Token Bypass RateSource
1–3 Push Prompts (Low)0.4%<0.02%0.0%Cisco Duo
4–10 Push Prompts (Moderate)1.8%0.05%0.0%Microsoft Security
11–30 Push Prompts (Bombing)3.8%0.06%0.0%Mandiant Threat Intel
Overnight Bombardment (1 AM–5 AM)5.2%0.08%0.0%Mandiant Threat Intel
Push + Accompanying Vishing Call14.6%1.20%0.0%CISA Advisories

Source: Cisco Duo State of the Auth, Microsoft Digital Defense Report, and Mandiant.

2. Attack Timing and Adversary Operational Cadence

Threat actors structure push bombardment around periods of vulnerability. Midnight bombardments disrupt sleep, causing victims to reach for their phones and tap the screen repeatedly to stop notifications. Telephony tactics are evaluated in our vishing statistics.

Operational WindowShare of MFA Bombing AttacksAverage Prompts SentMedian Time to CompromiseSource
Overnight Hours (01:00–05:00 Local)48.6%28 Prompts8.4 MinutesMandiant
Morning Commute (07:30–09:00 Local)22.4%18 Prompts14.2 MinutesCisco Duo
Standard Business Hours (09:00–17:00)18.2%14 Prompts22.8 MinutesMicrosoft Security
Weekend / Holiday Shifts10.8%26 Prompts11.6 MinutesCISA Advisories

Source: Mandiant M-Trends and Microsoft Threat Intelligence.

3. The MFA Technology Hierarchy and Vulnerability Profile

Authentication technologies exhibit stark differences in vulnerability to fatigue, social engineering, and session interception. Device hijacking risks are tracked in our sim-swap-fraud-statistics-2026.

MFA ModalityResistance to Fatigue BombingResistance to AiTM PhishingEnterprise Deployment ShareSource
FIDO2 / WebAuthn Hardware KeysComplete (100%)Complete (100%)18.4%CISA Advisories
Passkeys (Platform Cryptographic)Complete (100%)Complete (100%)24.2%Microsoft Security
Number Matching Authenticator AppVery High (98.4%)Low (Vulnerable to Proxies)68.5%Cisco Duo
Single-Tap Push App NotificationsExtremely Low (Vulnerable)Low (Vulnerable to Proxies)12.2%Cisco Duo
SMS / Voice Call One-Time CodesModerately Low (Vulnerable to SIM Swaps)Extremely Low42.0%CISA Advisories

Source: CISA Fact Sheets and Cisco Duo.

4. Organizational Impact and Identity Compromise Costs

An unauthorized MFA push approval grants access to internal corporate networks, enabling lateral movement, data exfiltration, and ransomware deployment. Identity risks are tracked in our identity theft statistics.

Impact MetricEnterprise ValueMid-Market ValueSmall Business ValueSource
Median Lateral Movement Time Post-MFA42 Minutes1.8 Hours3.4 HoursMandiant
Average Incident Containment Cost$340,000$165,000$82,000IBM Cost of Data Breach
Helpdesk Verification Reset Cost$54 per Ticket$42 per Ticket$28 per TicketGartner Identity
Share of Intrusions Involving Stolen Session28.6%22.4%16.8%CISA Advisories

Source: IBM Cost of a Data Breach and Mandiant.

5. Mitigation Strategies and Policy Implementation

Enterprise security teams rely on three complementary controls: number matching, geolocation context display, and automated prompt velocity throttling.

Defensive ImplementationFailure Reduction RateUser Friction RatingDeployment FeasibilitySource
Number Matching (Two-Digit Verification)98.4%LowImmediate (Cloud Identity)Microsoft Security
Location and App Context Matching84.2%NegligibleImmediate (Cloud Identity)Cisco Duo
Velocity Throttling (Max 3 Prompts / Hour)94.1%LowHighCISA Advisories
Phishing-Resistant FIDO2 Enforcement99.9%LowRequires Hardware LogisticsCISA Advisories

Source: Microsoft Digital Defense Report and CISA Guidance.

Summary: MFA Fatigue by the Numbers

DimensionBenchmark StatisticAuthoritative Source
Bombing Campaign Approval Rate3.8% of Target EmployeesCisco Duo Telemetry
Median Push Requests During Attack24 Consecutive PromptsMicrosoft Security
Overnight Attacks (01:00-05:00)48.6% of Incident VolumeMandiant Threat Intel
Number Matching Risk Reduction98.4% Failure EliminationMicrosoft Security
Enterprise Single-Tap MFA Phaseout76.8% of OrganizationsCisco Duo State of Auth
Share of Intrusions Involving MFA Bypass36.2% of Advanced BreachesCISA Advisories
Push Bombing + Vishing Approval Rate14.6% Success RateCISA Advisories
FIDO2 Phishing and Fatigue Resistance100% Cryptographic ImmunityCISA Guidance
AiTM Session Interception Growth+182% Year-over-YearMicrosoft Threat Intel
Average Compromise Elapsed Time14.5 Minutes Post-ApprovalMandiant M-Trends
Median Lateral Movement Window42 Minutes Post-BreachMandiant M-Trends
Rate-Limiting Protection Level94.1% Attack MitigationCisco Duo Telemetry
Passkey Enterprise Adoption Rate24.2% of OrganizationsMicrosoft Security
Enterprise Helpdesk Reset Cost$54 per Incident TicketGartner Identity
Hardware Security Key Adoption18.4% of Enterprise UsersCISA Guidance
Background Sync Misperception Rate62.4% of Approving VictimsCisco Duo Telemetry

Source: Compiled from CISA, Microsoft Digital Defense, Cisco Duo, and Mandiant.

Methodology and Sources

Data in this benchmark is compiled from identity threat telemetry published by the Cybersecurity and Infrastructure Security Agency (CISA), the Microsoft Digital Defense Report, Cisco Duo authentication logs, and Mandiant incident response reports.

Data watch: Prompt bombing statistics reflect logged authentication attempts across commercial identity providers (Microsoft Entra ID, Duo, Okta). Incidents involving phone call approvals or SMS intercepts are tracked separately under telecom fraud databases. Organizations operating legacy on-premise Active Directory federation services often lack centralized logging to detect prompt bombing patterns.

Last updated: September 2026. Published quarterly to track identity provider policy updates and passkey adoption.

Try VoxBooster — 3-day free trial.

Real-time voice cloning, soundboard, and effects — wherever you already talk.

  • No credit card
  • ~30ms latency
  • Discord · Teams · OBS
Try free for 3 days