What Is MFA Fatigue, and Why Are Employees Approving Fraudulent Login Prompts?
Attackers who already have a stolen password increasingly rely on a flood of login approval prompts wearing an employee down until one gets tapped accept, rather than breaking multi-factor authentication itself.


In Simple Terms (For Beginners)
MFA fatigue, also called push bombing, is when an attacker who already has your password repeatedly triggers login approval prompts on your phone until, out of confusion or annoyance, you approve one.
- MFA fatigue attacks don't break multi-factor authentication technically, they exploit the human tendency to approve a prompt just to make it stop.
- Attackers usually already have a valid password before starting this attack, meaning it's a second-stage technique, not an initial breach method.
- Number-matching and rate-limited prompts significantly reduce this risk compared to simple accept-or-deny push notifications.
THREAT INTEL · October 10, 2026 · 5 min · By Hardik Patel
What is MFA fatigue, and why do employees end up approving fraudulent login prompts? An attacker who already has a stolen password repeatedly triggers push-notification login requests on an employee's phone, often late at night or during a busy period, betting that the employee will eventually tap approve just to stop the notifications rather than recognising it as an active attack.
Why This Attack Works on People, Not Technology
Multi-factor authentication itself isn't broken in this attack. The attacker is exploiting the fact that a constant stream of notifications is annoying, confusing, and often arrives when someone isn't in a position to carefully evaluate each one.
Attacks are frequently timed for late evening or early morning, when an employee is more likely to approve a prompt reflexively just to silence their phone rather than pausing to consider whether they actually initiated a login.
Because the attacker already possesses a valid password at this stage, the only remaining barrier is that single approval tap, which is what makes this technique effective despite MFA being correctly configured.
How Attackers Get the Password in the First Place
This attack is almost always a second stage, following an earlier password compromise through phishing, a data breach involving reused credentials, or malware that captured login details.
Businesses focused only on MFA fatigue defences while ignoring password hygiene are addressing the symptom rather than the underlying exposure that made the attack possible in the first place.
Reviewing whether employee credentials have appeared in known breach data, and enforcing unique passwords rather than reused ones, closes off the step that makes this attack viable to begin with.
Defences That Actually Reduce This Risk
Number-matching MFA, where the employee must enter a code shown on the login screen rather than simply tapping approve, removes the reflexive-tap vulnerability this attack relies on.
Rate-limiting how many authentication prompts can be sent within a short window, and automatically locking an account after repeated failed or ignored prompts, blunts the flooding technique directly.
Employee awareness still matters as a backstop: knowing that an unexpected flood of login prompts should be reported immediately, not approved to make it stop, catches what technical controls miss.
Key Takeaways
- MFA fatigue attacks target human response to repeated notifications, not a technical flaw in multi-factor authentication.
- This technique is a second stage that requires a stolen password first, making password hygiene a relevant defence too.
- Number-matching authentication and prompt rate-limiting are more effective than simple accept-or-deny push notifications.
Frequently Asked Questions
Q: What should an employee do if they get an unexpected flood of login approval requests?
A: Deny every prompt, don't approve any of them to make the notifications stop, and report it to IT or security immediately, since it likely means the password is already compromised.
Q: Does switching from push notifications to SMS codes prevent this attack?
A: Not directly, though it changes the attack mechanics — SMS-based codes carry their own separate risks like SIM swapping, so number-matching push authentication is generally the stronger recommendation.
How iTechFixr Can Help
We review authentication configurations for exactly this gap and help businesses move from simple approve-or-deny push notifications to number-matching MFA, along with checking whether employee credentials have already surfaced in breach data. Our security awareness training also teaches staff to report unexpected approval prompts instead of accepting them.

Need Help With This?
Talk to Hardik directly about your organisation's cybersecurity needs — get a tailored response within 24 hours.


