31/07/2026
MFA fatigue is one of the most common attacks on small businesses today, and most owners don't know it by name.
The attacker already has the password (bought from a leak or stolen from another site). They log in. The MFA push hits your employee's phone. They tap "Deny." The attacker tries again 10 seconds later. Then again at 2am. Then during lunch. Eventually someone taps "Approve" just to make it stop. The attacker is in.
Uber got hit this way in 2022. Cisco too. It still works on small businesses every week because passwords keep leaking and the push prompt looks identical to a real login.
Three things close the gap, and none of them are expensive. Switch your team from "tap to approve" to number matching, which both Microsoft Authenticator and Duo support out of the box and takes about 10 minutes to enable in your tenant.
Then turn on geo-blocking or impossible-travel rules in your identity platform so logins from countries you don't operate in get blocked before the push ever fires.
Last, give your team one rule: if you get an MFA prompt you didn't ask for, deny it AND report it. The report is what catches the attacker mid-attempt.
The attacker doesn't need a fancy hack. They just need someone tired enough to tap "Approve."