Attackers Are Beating MFA With Nothing but Patience. Here’s the Fix.

Red padlock on a computer keyboard representing digital identity and MFA security
Photo by FlyD on Unsplash

The Weak Link Isn’t the Password Anymore

Most business owners think multi-factor authentication is the finish line. You turn it on, employees get a push notification on their phone, and the account is safe. For a few years that was mostly true. It isn’t anymore, and the gap has widened faster than most IT budgets have adjusted to it.

A joint advisory from CISA and the FBI, updated in 2025, names “push bombing,” also called MFA fatigue, as one of the most common ways attackers now get past multi-factor protections. The method doesn’t require any technical skill at all. An attacker who already has a stolen password simply logs in over and over, triggering approval request after approval request on the employee’s phone, until the employee gets annoyed, confused, or just tired at 11pm and taps approve to make it stop.

Verizon’s 2025 Data Breach Investigations Report backs this up with numbers: credential based attacks remain the leading cause of breaches, and MFA bypass techniques, push bombing chief among them, show up repeatedly in the incident data. The threat group known as Scattered Spider has built an entire playbook around it, combining push bombing with convincing help desk phone calls to reset credentials outright. Microsoft’s 2025 Digital Defense Report adds another layer: infostealer malware is now routinely used to steal session tokens directly from a browser, letting an attacker skip the MFA prompt entirely because they’re impersonating an already logged in session.

None of this means MFA has failed as a strategy, it means the version most small businesses deployed five years ago was built for a threat that’s moved on.

What Actually Closes the Gap

The fix isn’t more prompts, it’s smarter ones. Three changes make the biggest difference for Massachusetts businesses right now:

  • Turn on number matching. Instead of a simple approve or deny button, the employee has to type a number shown on their screen into the app. It sounds small, but it kills push bombing outright because a bored or distracted employee can’t approve a login by reflex.
  • Move privileged accounts to phishing-resistant MFA. FIDO2 security keys and passkeys can’t be phished, replayed, or bombed the way a push notification can. Owners, finance staff, and anyone with admin access are the accounts worth protecting this way first.
  • Add rate limiting and anomaly alerts. A login attempt from a new country followed by five approval requests in two minutes should never reach an employee’s phone without triggering a flag on the IT side first.

This is exactly the kind of layered thinking that belongs in a modern security stack, identity protections that assume a password will eventually leak, and are built to stop the attack at the next step instead.

The Real Cost of Waiting

The businesses getting hit aren’t the ones without MFA, they’re the ones who assumed turning it on was the end of the project. Attackers know most small and mid-sized companies stopped there, which is exactly why push bombing works as well as it does against this segment specifically.

None of the fixes above require replacing your existing systems or a six-month rollout. Number matching is usually a policy toggle. Phishing-resistant MFA for a handful of privileged accounts can be deployed in a week. What it does require is someone actually checking that the settings match the threat, not just the box that got checked when MFA was first turned on.

Get an Honest Look at Where You Stand

If you’re not sure whether your current MFA setup would stop a determined attacker or just slow them down for a night, that’s worth finding out before it’s tested for real. Schedule a free security assessment with Cloud9 and we’ll walk through your identity protections, find the gaps, and tell you plainly what needs to change.