How an MFA Fatigue Attack Actually Works
An MFA fatigue attack does not defeat multi-factor authentication; it waits for a person to approve it. The attacker already holds a working password and triggers push prompts repeatedly, often late at night, until the account holder taps approve to stop the noise. Ten prompts in a minute is a common pattern.
The design of the attack is social rather than technical, which is why it defeats employees who have passed every phishing test. Nothing on the screen is fake, the prompt is genuinely from the company's own identity provider, and the only wrong element is that the person did not start it. Kept out of the video entirely is the defensive configuration: which conditional access rules are enforced, which accounts are exempt, and what the lockout thresholds are should stay in the security runbook rather than in a video sent to everyone.
The attack is set out across eight scenes: two on how the attacker gets the password in the first place, two on the prompt sequence as the employee experiences it, one on the phone call that often follows pretending to be IT support, one on the correct response, one on how to report it, and one on what the organisation does afterwards.

