Multi-factor authentication is one of the best protections a healthcare organization can use, but it is not magic. Attackers have learned that if they cannot get around the second factor, they can try to wear down the person holding it. The technique has several names: MFA fatigue, push bombing and prompt bombing. All of them rely on the same human weakness.
If your staff approve sign-in requests with a tap on a phone, this is worth understanding. It affects everyone from the front desk to the administrator, and the defenses are practical.
The attack begins with a stolen password. Credentials leak through phishing, reused passwords from other breaches or malware. On its own, a stolen password should not be enough to get into an account that requires MFA.
So the attacker tries to sign in over and over. Each attempt sends a push notification to the real user's phone: "Approve sign-in?" The notifications can arrive in the middle of the night, during a busy shift or while the person is driving. Eventually the user may approve one just to make it stop, or assume it is a glitch, or tap the wrong button while distracted.
Some attackers add a second step. They contact the target by phone, text or chat, pretending to be IT support, and say something like "You will see some prompts, please approve them so we can fix the problem." Combined with the barrage, this can be convincing.
Healthcare environments make this attack more effective than it would be in a quiet office.
Staff are interrupted constantly and respond to alerts on reflex.
Many people have phones silenced or tucked into a pocket and see a prompt only after the damage is done.
Shared work areas and shift work mean sign-in requests are often expected, so one more does not feel strange.
Staff may not know who to call, or may fear getting in trouble for a mistake.
With number matching, the sign-in screen displays a number, and the user must type that number into the authenticator app to approve. An attacker triggering prompts from elsewhere cannot supply the number to the real user, and a user who is not currently signing in has no number to enter. Simple taps stop working as an attack path. Microsoft and other major identity providers support this approach, so check your settings and turn it on if it is not already.
Some authenticator apps can show where the request came from, which application is asking and the approximate location. A prompt that says the sign-in is coming from a country where you have no staff is an obvious red flag.
Configure your identity system to limit repeated failed or repeated prompt requests. After a set number of attempts, the account should pause or require extra verification, which prevents an endless stream of prompts.
Phishing-resistant methods, such as hardware security keys or passkeys, do not depend on a user tapping approve at all. They are not practical for every employee, but they are a good fit for administrators, IT staff, finance and anyone with broad access to patient data.
Have someone watch for patterns: many failed MFA prompts for one user, sign-ins from unusual places or a successful sign-in right after a string of denials. Those patterns are early warnings.
Technology only goes so far. Staff need to know exactly what to do, in terms that are easy to remember.
Never approve a prompt you did not start. If you are not signing in, deny it.
Report unexpected prompts right away. Even denied prompts mean someone has your password, which needs to be changed.
IT will never ask you to approve a prompt over the phone or in chat. Say this plainly and repeat it.
Make reporting safe. Staff who admit to a mistake quickly protect the organization. Staff who fear blame stay silent.
Short, repeated reminders work better than a long annual session.
Move quickly. Have the user change their password, sign out of all active sessions, and review the account for suspicious activity such as new forwarding rules or newly registered devices. Report the incident to your IT provider. Depending on what the account could access, you may need to evaluate whether protected health information was exposed under the HIPAA Breach Notification Rule.
MFA fatigue attacks do not break MFA. They exploit the person using it. Number matching, sensible limits and clear instructions to staff remove most of the attacker's advantage. UnityCare IT helps healthcare organizations review their MFA settings, turn on stronger options and train their teams, so a late-night barrage of prompts is met with a confident "deny" and a quick call.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172