Sustained MFA push bombing campaigns succeed in tricking employees into approving unauthorized logins in up to 3.8% of attacks, prompting 76.8% of global enterprises to eliminate simple single-tap authentications. As explored in our password-security-statistics-2026 and account-takeover-statistics-2026, legacy two-factor methods that rely on human willpower to deny notifications are actively subverted by cybercriminal syndicates. The data below synthesizes empirical threat telemetry from CISA, the Microsoft Digital Defense Report, Cisco Duo, and Mandiant.
TL;DR
- Up to 3.8% of employees approve an unauthorized MFA push during sustained bombardment (Cisco Duo).
- Attackers send a median of 24 push requests in 12 minutes during prompt bombing (Microsoft).
- 48.6% of MFA fatigue campaigns are initiated during overnight hours between 1:00 AM and 5:00 AM (Mandiant).
- Enforcing number matching reduces fraudulent push approvals by 98.4% (Microsoft).
- 36.2% of corporate identity intrusions involve MFA bypass or session hijacking (CISA).
- 76.8% of enterprise IT departments have decommissioned single-tap “Approve” notifications (Cisco Duo).
- The average time between initial push bombardment and unauthorized account access is 14.5 minutes (Mandiant).
- FIDO2 hardware tokens eliminate 100% of remote prompt bombing and AiTM phishing risks (CISA).
- Adversary-in-the-middle (AiTM) reverse proxy attacks targeting session cookies grew 182% year-over-year (Microsoft).
- 62.4% of users who approved a rogue prompt reported believing it was a background system sync (Cisco Duo).
- Telephony-based voice MFA prompts suffer a 7.2% unauthorized approval rate (CISA).
- Rate-limiting consecutive push requests to 3 per hour prevents 94.1% of automated bombing scripts (Cisco Duo).
1. Attack Frequency and Employee Approval Rates
When threat actors acquire corporate credentials through infostealer logs or phishing, MFA push fatigue serves as the primary barrier-breaker. Repetitive notifications induce cognitive overload and frustration. Credential theft vectors are analyzed in our phishing statistics.
| Attack Intensity Metric | Single-Tap Push Approval Rate | Number Matching Approval Rate | Hardware Token Bypass Rate | Source |
|---|---|---|---|---|
| 1–3 Push Prompts (Low) | 0.4% | <0.02% | 0.0% | Cisco Duo |
| 4–10 Push Prompts (Moderate) | 1.8% | 0.05% | 0.0% | Microsoft Security |
| 11–30 Push Prompts (Bombing) | 3.8% | 0.06% | 0.0% | Mandiant Threat Intel |
| Overnight Bombardment (1 AM–5 AM) | 5.2% | 0.08% | 0.0% | Mandiant Threat Intel |
| Push + Accompanying Vishing Call | 14.6% | 1.20% | 0.0% | CISA Advisories |
Source: Cisco Duo State of the Auth, Microsoft Digital Defense Report, and Mandiant.
2. Attack Timing and Adversary Operational Cadence
Threat actors structure push bombardment around periods of vulnerability. Midnight bombardments disrupt sleep, causing victims to reach for their phones and tap the screen repeatedly to stop notifications. Telephony tactics are evaluated in our vishing statistics.
| Operational Window | Share of MFA Bombing Attacks | Average Prompts Sent | Median Time to Compromise | Source |
|---|---|---|---|---|
| Overnight Hours (01:00–05:00 Local) | 48.6% | 28 Prompts | 8.4 Minutes | Mandiant |
| Morning Commute (07:30–09:00 Local) | 22.4% | 18 Prompts | 14.2 Minutes | Cisco Duo |
| Standard Business Hours (09:00–17:00) | 18.2% | 14 Prompts | 22.8 Minutes | Microsoft Security |
| Weekend / Holiday Shifts | 10.8% | 26 Prompts | 11.6 Minutes | CISA Advisories |
Source: Mandiant M-Trends and Microsoft Threat Intelligence.
3. The MFA Technology Hierarchy and Vulnerability Profile
Authentication technologies exhibit stark differences in vulnerability to fatigue, social engineering, and session interception. Device hijacking risks are tracked in our sim-swap-fraud-statistics-2026.
| MFA Modality | Resistance to Fatigue Bombing | Resistance to AiTM Phishing | Enterprise Deployment Share | Source |
|---|---|---|---|---|
| FIDO2 / WebAuthn Hardware Keys | Complete (100%) | Complete (100%) | 18.4% | CISA Advisories |
| Passkeys (Platform Cryptographic) | Complete (100%) | Complete (100%) | 24.2% | Microsoft Security |
| Number Matching Authenticator App | Very High (98.4%) | Low (Vulnerable to Proxies) | 68.5% | Cisco Duo |
| Single-Tap Push App Notifications | Extremely Low (Vulnerable) | Low (Vulnerable to Proxies) | 12.2% | Cisco Duo |
| SMS / Voice Call One-Time Codes | Moderately Low (Vulnerable to SIM Swaps) | Extremely Low | 42.0% | CISA Advisories |
Source: CISA Fact Sheets and Cisco Duo.
4. Organizational Impact and Identity Compromise Costs
An unauthorized MFA push approval grants access to internal corporate networks, enabling lateral movement, data exfiltration, and ransomware deployment. Identity risks are tracked in our identity theft statistics.
| Impact Metric | Enterprise Value | Mid-Market Value | Small Business Value | Source |
|---|---|---|---|---|
| Median Lateral Movement Time Post-MFA | 42 Minutes | 1.8 Hours | 3.4 Hours | Mandiant |
| Average Incident Containment Cost | $340,000 | $165,000 | $82,000 | IBM Cost of Data Breach |
| Helpdesk Verification Reset Cost | $54 per Ticket | $42 per Ticket | $28 per Ticket | Gartner Identity |
| Share of Intrusions Involving Stolen Session | 28.6% | 22.4% | 16.8% | CISA Advisories |
Source: IBM Cost of a Data Breach and Mandiant.
5. Mitigation Strategies and Policy Implementation
Enterprise security teams rely on three complementary controls: number matching, geolocation context display, and automated prompt velocity throttling.
| Defensive Implementation | Failure Reduction Rate | User Friction Rating | Deployment Feasibility | Source |
|---|---|---|---|---|
| Number Matching (Two-Digit Verification) | 98.4% | Low | Immediate (Cloud Identity) | Microsoft Security |
| Location and App Context Matching | 84.2% | Negligible | Immediate (Cloud Identity) | Cisco Duo |
| Velocity Throttling (Max 3 Prompts / Hour) | 94.1% | Low | High | CISA Advisories |
| Phishing-Resistant FIDO2 Enforcement | 99.9% | Low | Requires Hardware Logistics | CISA Advisories |
Source: Microsoft Digital Defense Report and CISA Guidance.
Summary: MFA Fatigue by the Numbers
| Dimension | Benchmark Statistic | Authoritative Source |
|---|---|---|
| Bombing Campaign Approval Rate | 3.8% of Target Employees | Cisco Duo Telemetry |
| Median Push Requests During Attack | 24 Consecutive Prompts | Microsoft Security |
| Overnight Attacks (01:00-05:00) | 48.6% of Incident Volume | Mandiant Threat Intel |
| Number Matching Risk Reduction | 98.4% Failure Elimination | Microsoft Security |
| Enterprise Single-Tap MFA Phaseout | 76.8% of Organizations | Cisco Duo State of Auth |
| Share of Intrusions Involving MFA Bypass | 36.2% of Advanced Breaches | CISA Advisories |
| Push Bombing + Vishing Approval Rate | 14.6% Success Rate | CISA Advisories |
| FIDO2 Phishing and Fatigue Resistance | 100% Cryptographic Immunity | CISA Guidance |
| AiTM Session Interception Growth | +182% Year-over-Year | Microsoft Threat Intel |
| Average Compromise Elapsed Time | 14.5 Minutes Post-Approval | Mandiant M-Trends |
| Median Lateral Movement Window | 42 Minutes Post-Breach | Mandiant M-Trends |
| Rate-Limiting Protection Level | 94.1% Attack Mitigation | Cisco Duo Telemetry |
| Passkey Enterprise Adoption Rate | 24.2% of Organizations | Microsoft Security |
| Enterprise Helpdesk Reset Cost | $54 per Incident Ticket | Gartner Identity |
| Hardware Security Key Adoption | 18.4% of Enterprise Users | CISA Guidance |
| Background Sync Misperception Rate | 62.4% of Approving Victims | Cisco Duo Telemetry |
Source: Compiled from CISA, Microsoft Digital Defense, Cisco Duo, and Mandiant.
Methodology and Sources
Data in this benchmark is compiled from identity threat telemetry published by the Cybersecurity and Infrastructure Security Agency (CISA), the Microsoft Digital Defense Report, Cisco Duo authentication logs, and Mandiant incident response reports.
- CISA Identity and Access Management Advisories
- Microsoft Digital Defense Report
- Cisco Duo State of the Auth Report
- Mandiant M-Trends Incident Response
- IBM Security Cost of a Data Breach Report
Data watch: Prompt bombing statistics reflect logged authentication attempts across commercial identity providers (Microsoft Entra ID, Duo, Okta). Incidents involving phone call approvals or SMS intercepts are tracked separately under telecom fraud databases. Organizations operating legacy on-premise Active Directory federation services often lack centralized logging to detect prompt bombing patterns.
Last updated: September 2026. Published quarterly to track identity provider policy updates and passkey adoption.