RESOURCES · SECURITY & EMAIL

MFA fatigue attacks,
explained

Ever had a burst of "approve this sign-in?" notifications pop up on your phone when you weren't even logging in? That's not a glitch — it's an attack. It's called MFA fatigue, or prompt-bombing, and it's designed to wear you down until you tap "approve". Here's how it works, and how to beat it.

Applies to: Anyone using app-based MFA Read: ~4 min Level: Non-technical
Quick answer

An attacker who already has your password spams you with MFA approval prompts, hoping you'll tap "yes" out of habit, annoyance or confusion. If you do, they're straight in. The rule: never approve a prompt you didn't personally trigger — deny it, and report it, because a flood of prompts means someone already knows your password.

HOW IT WORKS

Wearing you down until you tap yes.

The attacker already has your password — from a data breach, from reusing the same password across sites, or from an earlier phishing email. But they still need to get past your MFA. So they try to log in over and over, and each attempt fires an approval prompt to your phone. Your phone floods with notifications — often late at night, when you're tired and off guard — and they're betting you'll approve one just to make it stop, or assume it's some kind of system error and tap it away.

WHY IT WORKS

It's a numbers game on your patience.

RED FLAGS

How to know it's an attack.

WHAT TO DO

Deny, then lock it down.

  1. Never approve a prompt you didn't trigger — deny itIf you weren't logging in, the prompt isn't yours to approve. Tap "deny" (or ignore it), and don't tap "approve" to make the noise stop.
  2. Change your password immediatelyThe attacker already has your current one — that's why the prompts are arriving. Change it straight away, from a device you trust, and anywhere you reused it.
  3. Report it to your IT or security teamLet them know so they can check the account for any successful sign-ins and lock it down properly.
  4. Ask about stronger MFAAsk about "number-matching" MFA (where you type a number shown on the login screen) and phishing-resistant MFA like passkeys — both shut this attack down.
A wave of prompts means your password is already compromised. Approving one hands over the account entirely — but even if you ignore every prompt, the attacker still knows your password. It needs changing right away, no matter what.
STRONGER SIGN-INS

Is your MFA the kind that can be nagged into a "yes"?

Simple "tap to approve" MFA is exactly what prompt-bombing preys on. Our free IT Health Check reviews your MFA settings and shows you how to move to number-matching or phishing-resistant methods — so a random tap can never let an attacker in, and your team knows exactly what to do when the prompts start.

KEEP READING

Related resources