



Multi-factor authentication (MFA) was once considered the gold standard of identity security. Add a second factor — a one-time password, a push notification, a hardware token — and you dramatically reduce your exposure to credential-based attacks. Indian enterprises have invested heavily in MFA rollouts over the last several years, driven by CERT-In advisories, RBI guidelines for the BFSI sector, and growing awareness of phishing and account-compromise threats.
But threat actors adapt. A technique known as MFA fatigue — also called push bombing or MFA prompt bombing — has become one of the most reliable ways for attackers to compromise accounts protected by push-based authentication. High-profile breaches at major technology companies have demonstrated in uncomfortable detail just how effective this technique can be. Indian enterprises, many of which rely on Microsoft Authenticator, Duo, or similar push-based solutions, are directly in the crosshairs.
The mechanics are deceptively simple. An attacker obtains a user’s username and password — through phishing, credential stuffing from a leaked database, or purchasing credentials on a darknet market. With valid credentials in hand, they repeatedly trigger authentication push notifications to the victim’s registered device, often dozens of times in rapid succession, sometimes in the middle of the night.
The goal is not to crack the MFA code. The goal is to exhaust the user’s patience. After receiving the twentieth push notification in fifteen minutes, many users — particularly those who are tired, distracted, or frustrated — tap “Approve” just to make the notifications stop. At that moment, the attacker has full access to the account.
Variants of the attack layer social engineering on top: attackers call the victim, impersonate IT helpdesk staff, and say something like, “We are running a security audit — please approve the push notification we just sent.” The victim, now believing this is a legitimate IT request, complies willingly.
The risk for Indian organisations is elevated for several structural reasons:
Understanding the attack progression helps security teams identify where controls can break the chain:
India’s Computer Emergency Response Team (CERT-In) issued direction 20(3)/2022-CERT-In in April 2022, requiring organisations in critical sectors to report cybersecurity incidents — including unauthorised account access — within six hours of detection. An MFA-bypass-driven account takeover that touches corporate email or cloud infrastructure qualifies as a reportable incident under this directive.
The six-hour window is demanding. From the moment your SOC analyst detects an anomalous login, you have less than a working shift to investigate, contain, and notify. That timeline is achievable only if detection and response processes are automated — not when analysts are manually correlating logs across disconnected systems. For organisations without in-house coverage, a managed SOC as a Service with round-the-clock 24/7 monitoring ensures anomalous sign-ins are investigated the moment they occur — not the next morning.
Defending against MFA fatigue requires layered controls across identity, network, and endpoint. Here is a prioritised checklist for Indian enterprise security teams:
Even if an attacker succeeds in stealing an authenticated identity, Zero Trust Network Access (ZTNA) limits the damage. ZTNA enforces least-privilege access to applications: a compromised account can only reach the specific applications it is authorised for, from a device that meets the security posture baseline. It cannot freely traverse the network or access resources beyond its defined scope.
PJ Networks deploys Fortinet’s ZTNA solution — integrated with FortiGate and FortiClient — as part of its managed security portfolio. For clients who have experienced MFA-bypass incidents, ZTNA reduces blast radius by preventing lateral movement from a compromised identity. Combined with continuous device posture checks, even a valid session token obtained through MFA fatigue grants no unrestricted network access.
Detecting and responding to MFA fatigue attacks at scale requires a SecOps platform that can ingest identity signals alongside network, endpoint, and cloud telemetry and surface meaningful, correlated alerts in near real-time. For our clients, PJ Networks deploys and operates PrahiX Ora, a unified SecOps platform built by PrahiX Tech Pvt Ltd. As its primary field deployment and operations partner, PJ Networks brings Ora to enterprise environments across India. Here is how each pillar of the platform strengthens your defence against identity-based attacks:
SIEM — Correlation and Attack Storyline Reconstruction: PrahiX Ora’s SIEM ingests logs from identity providers (Entra ID, Okta, Google Workspace), FortiGate, endpoint agents, and cloud platforms. Correlation rules are mapped to MITRE ATT&CK tactics — specifically Credential Access and Initial Access — and trigger alerts when push-flood patterns or impossible-travel sequences are detected. Graph-based attack storyline reconstruction links authentication events to subsequent mailbox activity, network connections, and file access, giving analysts a complete picture rather than isolated signals. Tiered retention (hot, cold, and archive) supports CERT-In’s 180-day in-country log retention direction, ensuring you have the historical depth needed for regulatory response and forensic investigations.
NMS — Network Visibility Across Multi-Vendor Estates: Once an attacker has a foothold in an identity, they probe the network. PrahiX Ora’s Network Management System provides unified observability across firewalls, switches, access points, and WAN/SD-WAN links. LLDP/CDP topology discovery maps the network automatically; ML-based anomaly detection flags unusual lateral movement — a compromised account accessing servers it has never touched, or an endpoint scanning internal subnets. For Indian enterprises with fragmented NOC visibility across multi-vendor estates, this single-pane view closes a critical blind spot.
Video Surveillance (VMS) — Physical-Digital Security Correlation: For manufacturing, retail, and multi-site organisations, PrahiX Ora’s video surveillance (VMS) capability — supporting ONVIF, Hikvision, and Dahua cameras with video analytics — allows physical and network security events to be correlated in one operations view. An after-hours authentication from a facility that shows no staff present on camera is a meaningful red flag that siloed physical and IT security systems cannot surface. This is particularly relevant for Indian enterprises managing distributed estates where the physical and digital threat surfaces have historically been managed separately.
SOAR — Automated Response Within the CERT-In Window: The SOAR capability runs playbook automation with pre-built connectors and automated response actions. For an MFA fatigue event in progress, a response playbook can automatically disable the targeted account, revoke active sessions, and push an updated IP blocklist to FortiGate — all within minutes of alert generation. This level of automation is what makes CERT-In’s six-hour incident reporting window realistic in practice. By the time your analyst begins drafting the notification, containment has already progressed significantly. To explore how PrahiX Ora could be deployed and operated in your environment, reach out to PJ Networks for an assessment.
If your SOC detects a potential MFA fatigue attack in progress, here is the recommended immediate response sequence:
Given the current threat landscape, here is a pragmatic prioritisation for Indian enterprise security teams:
The security industry has said for years that identity is the new perimeter. MFA fatigue attacks make that statement operationally concrete. Threat actors no longer need to break through firewalls — they convince employees to hand over authenticated sessions. The defensive response must be equally identity-centric: phishing-resistant authentication methods, Zero Trust access controls, and continuous behavioural monitoring of every session.
For Indian enterprises navigating the dual pressures of DPDP Act compliance and CERT-In’s incident reporting requirements, a robust identity security posture is not optional — it is the foundation on which every other security investment depends.
PJ Networks helps Indian enterprises design, deploy, and operate identity-aware security architectures — from FortiGate-based ZTNA and FortiClient endpoint protection to 24/7 NOC/SOC monitoring. If your organisation is assessing its MFA posture or preparing for a DPDP or CERT-In compliance review, contact PJ Networks for a no-obligation security consultation.