Business phones system melbourne
All Posts / MFA Fatigue Attacks: How to Protect Your Melbourne Business in 2026
Blog

MFA Fatigue Attacks: How to Protect Your Melbourne Business in 2026

Abhishek Bhargva

Telco ICT

14/05/2026

MFA Fatigue Attacks: How to Protect Your Melbourne Business in 2026

Multi-factor authentication (MFA) is one of the smartest cybersecurity moves your business can make. It blocks the vast majority of unauthorised login attempts, and most IT professionals will tell you it is non-negotiable in 2026. But here is the thing: cybercriminals have found a way around it that does not involve hacking your systems at all. They exploit something far harder to patch: human fatigue.

MFA fatigue attacks Melbourne businesses are seeing right now rely on a simple but effective trick. If an attacker already has your stolen usernames and passwords, they can bombard your staff with endless push notifications until someone, worn down and frustrated, taps “approve” just to make it stop. No zero-day exploit needed. No advanced malware. Just persistence, and a moment of human weakness. Businesses using professional managed IT services and cybersecurity monitoring are often better equipped to detect suspicious login activity before attackers gain access to critical systems.

According to the ASD’s ACSC Annual Cyber Threat Report 2024-25, over 84,700 cybercrime reports were submitted in FY2024-25, roughly one every six minutes. Australian SMBs are firmly in the crosshairs.

In this post, you will learn exactly what an MFA fatigue attack is, why Melbourne businesses are especially at risk, and the practical steps you can take right now to stop one before it happens.

What Is an MFA Fatigue Attack? (And Why MFA Is Not Enough on Its Own)

An MFA fatigue attack, also called push bombing or prompt bombing, is a type of social engineering attack. Here is how it works, step by step:

  • The attacker gets your credentials. Usually through phishing, a data breach, or buying stolen usernames and passwords on the dark web.
  • They attempt to log in repeatedly. Each attempt triggers a push notification or approval request on the employee’s phone or authenticator app.
  • The notifications keep coming. Sometimes dozens of them, often late at night or early in the morning when people are half-asleep or distracted.
  • The employee gives in. Out of frustration, confusion, or after a fake “IT support” call telling them to approve the request, they tap “approve.”
  • The attacker is in. Full access, with no technical barrier breached at all.

The attack works because of how common approval requests are in everyday work life. People log into Microsoft 365, cloud services, and remote access tools dozens of times a day. When a push notification appears, approving it feels almost automatic.

What makes this particularly dangerous is that the second factor of verification has been turned against the user. The MFA method itself becomes the weapon. A simple “yes/no” push notification-based MFA, like older versions of Microsoft Authenticator without number matching, is especially vulnerable to this tactic.

Research from CyberCX’s 2025 DFIR Threat Report found that 75% of Business Email Compromise (BEC) incidents in 2024 involved session hijacking or MFA bypass, up from 38.5% the year before. MFA has not become useless, but relying on basic push-based MFA without additional controls is leaving the door open.

Why Australian SMBs Are Especially Vulnerable to MFA Fatigue Attacks

You might assume that cybercriminals focus on big enterprise targets. The reality is that Australian small businesses are highly attractive precisely because they are less fortified.

Here is why Australian SMBs face a higher risk:

  • Fewer dedicated security resources. Many small businesses in Melbourne rely on a generalist IT person or outsourced support, rather than a dedicated security team monitoring for suspicious activity around the clock.
  • Remote work has expanded the attack surface. With staff logging in from home, cafes, and co-working spaces, remote access tools and cloud services have become central to how businesses operate. Each new access point is a potential entry for an attacker.
  • MFA methods are often outdated. Many businesses set up basic push notification MFA years ago and have not revisited the settings. Older MFA configurations without number matching or context-aware prompts are much easier to exploit.
  • Staff training gaps. Finance staff and other high-value targets often have not received specific training on recognising suspicious approval requests or push bombing attempts.
  • Credential exposure is widespread. With data breaches affecting major platforms regularly, stolen usernames and passwords are cheap and easy to obtain. Once an attacker has credentials, an MFA fatigue attack is the logical next step.

The ACSC Annual Cyber Threat Report confirms that the average cost of a cybercrime incident for small businesses rose to $56,600 per report in FY2024-25. For medium businesses, that figure climbs to $97,200. These are not costs most Melbourne SMBs can absorb easily.

The ACSC has specifically flagged push-bombing as a growing technique targeting Australian organisations across all sectors and sizes. It is not a threat on the horizon. It is happening now.

5 Ways to Stop MFA Fatigue Attacks and Protect Your Business

The good news is that defending against MFA fatigue attacks does not require rebuilding your entire security stack. It requires layering smarter controls on top of what you already have. Here are the five most effective approaches to protect your business:

1. Switch to Phishing-Resistant MFA

This is the single most impactful change you can make. Phishing-resistant MFA, such as FIDO2 hardware security keys (like a YubiKey) or passkeys, works differently from push-based MFA. Instead of sending an approval request to a phone, the authentication is bound to a specific website or application. An attacker cannot intercept or replay it, even if they have your password.

The ASD’s Essential Eight framework at Maturity Level 3 specifically requires phishing-resistant MFA for all users. For Melbourne businesses that handle sensitive data or are on a path to Essential Eight compliance, this is a critical upgrade.

Options include:

  • Hardware security keys such as YubiKey or similar FIDO2 devices
  • Microsoft Authenticator with passkey support (available in current versions)
  • Windows Hello for Business for device-bound authentication

2. Enable Number Matching in Microsoft Authenticator

If you are using Microsoft Authenticator, enabling number matching is a quick win that directly defeats push bombing. Instead of a simple “approve/deny” prompt, the employee sees a two-digit number on the sign-in screen and must type that number into the Authenticator app to confirm. An attacker triggering a notification cannot complete the login because they do not see the number.

Microsoft’s own documentation confirms that number matching is now built into Microsoft security defaults as a countermeasure against MFA fatigue attacks. If you have not verified it is active in your tenant, that is worth checking today.

3. Set Limits on Approval Requests

Your Microsoft 365 or identity platform should be configured to limit how many MFA challenges a user can receive within a set timeframe. When a user is bombarded with requests, the system should lock the account temporarily and alert your IT team, rather than allowing the requests to continue indefinitely. This cuts off the push bombing attack before it has time to wear down the user.

4. Implement Conditional Access Policies

Conditional access policies in Microsoft Entra ID allow you to set rules around when and how MFA is required. For example, you can require stronger authentication for logins from unfamiliar locations or devices, block access entirely from high-risk countries, and require additional verification for privileged accounts and remote access tools.

Microsoft Learn recommends using authentication strength policies within Conditional Access to enforce phishing-resistant MFA for high-risk scenarios. This is particularly important for admin accounts and finance staff who are common targets.

5. Run Targeted Staff Training

Technology controls are only part of the picture. Your employees are the last line of defence when a push bombing attack is in progress. Staff training should cover:

  • What an MFA fatigue attack looks like and why it happens
  • The rule of thumb: if you receive an approval request you did not initiate, deny it and report it immediately
  • What to do if they receive a suspicious “IT support” call asking them to approve a request
  • How to report suspicious MFA activity to your internal team or managed IT provider

Regular training, even short refresher sessions, significantly reduces the likelihood of a successful attack. This is especially important for remote work environments where staff are less likely to have a colleague nearby to consult.

Microsoft 365 and Entra ID: Specific Settings to Harden Against MFA Bypass

If your Melbourne business runs on Microsoft 365, these are the specific settings you should review and update as part of your cybersecurity defence in 2026:

Setting What It Does Where to Find It
Number Matching Requires users to enter a displayed number in the Authenticator app, defeating push bombing Entra ID > Authentication Methods > Microsoft Authenticator
Additional Context Shows the app name and location in the MFA prompt so users can spot suspicious requests Entra ID > Authentication Methods > Microsoft Authenticator
Conditional Access Policies Restricts or strengthens login requirements based on location, device, and risk signals Entra ID > Security > Conditional Access
Authentication Strength Enforces phishing-resistant MFA methods for privileged accounts or sensitive apps Entra ID > Security > Conditional Access > Authentication Strength
Report Suspicious Activity Allows users to flag an MFA prompt as suspicious, triggering a High User Risk alert Entra ID > Security > Authentication Methods
Sign-in Risk Policies Automatically requires re-authentication or blocks access when a risky login is detected Entra ID > Security > Identity Protection
Legacy Authentication Block Prevents attackers from using older protocols that bypass MFA entirely Entra ID > Security > Conditional Access

A few additional steps worth taking:

  • Audit privileged accounts. Admin accounts should require phishing-resistant MFA as a minimum. If a Microsoft 365 admin account is compromised, the impact is far greater than a standard user account.
  • Review your MFA registration policies. Make sure employees cannot self-register new MFA methods without verification. Attackers who compromise an account sometimes try to register their own MFA device to lock the real user out.
  • Enable sign-in risk detection. Microsoft Entra ID Protection can flag unusual logins, such as a login from Melbourne followed minutes later by one from overseas, and require additional verification automatically.

What to Do If You Suspect an MFA Fatigue Attack Is in Progress

If an employee reports a flood of unexpected push notifications, time is critical. Here is what to do:

Immediate actions:

  • Tell the affected employee to deny all further approval requests and not to accept anything until told otherwise
  • Reset the employee’s password immediately, which invalidates the credentials the attacker is using
  • Revoke all active sign-in sessions for that account in Microsoft Entra ID (Admin Centre > Users > Revoke Sessions)
  • Check the sign-in logs in Entra ID for suspicious login attempts, particularly from unusual locations or at unusual times
  • Alert your managed IT provider or internal security team

After the immediate response:

  • Determine how the attacker obtained the credentials in the first place: was it a phishing email, a known data breach, or password reuse across other services?
  • Check whether any data was accessed during the period of the attack
  • Review your audit logs for any changes made to the account, mailbox rules, or forwarding settings
  • Use this event as a trigger to accelerate phishing-resistant MFA rollout across the organisation

Business continuity planning should also account for scenarios like this. If a key account is compromised and locked down, do you have a backup process for critical operations? Thinking through these scenarios in advance makes a real difference to how quickly you recover.

Think Your Microsoft 365 Environment Is Properly Hardened?

Most Melbourne businesses that come to us for a security review are surprised by what they find. Default MFA settings, legacy authentication still enabled, and no conditional access policies in place. These are not difficult problems to fix, but you need to know they exist first.

Telco ICT Group offers a security review that checks your MFA configuration, conditional access policies, identity protection settings, and Office 365 setup against current best practices. We also provide managed IT services that keep these settings maintained and monitored on an ongoing basis.

Book your security review today and know exactly where your Melbourne business stands.

Frequently Asked Questions

Is MFA still worth using if fatigue attacks exist?
Absolutely. MFA still blocks the vast majority of account takeover attempts. The solution is to upgrade to phishing-resistant MFA (such as FIDO2 hardware keys or passkeys) rather than abandoning MFA altogether. Basic push-based MFA is still far better than no second factor at all.

How common are MFA fatigue attacks in Australia?
They are increasingly common and growing. The ACSC has specifically flagged push-bombing as a rising technique targeting Australian organisations of all sizes and sectors. With data breaches making stolen credentials widely available, any attacker with a password and a target list can attempt this attack.

Can my firewall stop MFA fatigue attacks?
Not directly. These attacks exploit human behaviour rather than network vulnerabilities, so a firewall alone will not stop them. However, firewall services combined with conditional access policies, identity protection tools, and user training form a strong layered defence.

What MFA methods are phishing-resistant?
Phishing-resistant MFA methods include FIDO2 hardware security keys (like YubiKey), passkeys, and Windows Hello for Business. These methods bind authentication to the specific website or device, so they cannot be intercepted or replayed by an attacker even if they have your password.

Does the Essential Eight framework address MFA fatigue attacks?
Yes. The ASD Essential Eight framework requires phishing-resistant MFA at Maturity Level 3. Australian businesses working toward Essential Eight compliance will need to move beyond basic push notifications to stronger authentication methods, which directly address the MFA fatigue attack vector.