Ever had a burst of "approve this sign-in?" notifications pop up on your phone when you weren't even logging in? That's not a glitch — it's an attack. It's called MFA fatigue, or prompt-bombing, and it's designed to wear you down until you tap "approve". Here's how it works, and how to beat it.
An attacker who already has your password spams you with MFA approval prompts, hoping you'll tap "yes" out of habit, annoyance or confusion. If you do, they're straight in. The rule: never approve a prompt you didn't personally trigger — deny it, and report it, because a flood of prompts means someone already knows your password.
The attacker already has your password — from a data breach, from reusing the same password across sites, or from an earlier phishing email. But they still need to get past your MFA. So they try to log in over and over, and each attempt fires an approval prompt to your phone. Your phone floods with notifications — often late at night, when you're tired and off guard — and they're betting you'll approve one just to make it stop, or assume it's some kind of system error and tap it away.
Simple "tap to approve" MFA is exactly what prompt-bombing preys on. Our free IT Health Check reviews your MFA settings and shows you how to move to number-matching or phishing-resistant methods — so a random tap can never let an attacker in, and your team knows exactly what to do when the prompts start.