01
When MFA becomes a notification approved out of fatigue
In push bombing, the attacker already has the password and triggers MFA prompts until the user approves one.
- Enable number matching
- Remove weak methods where possible
- Alert on repeated MFA prompts
- Prioritize passkeys or FIDO2 for critical accounts
Blurtek tunes identity and conditional access so MFA protects without blocking users.
Solicitar diagnóstico