MFA Prompt Bombing
Have you heard about this? You think you’ve done everything right. Strong password, unique for every account, and multi-factor authentication (2FA) turned on everywhere it’s offered. You should be safe, right?
Not quite. Attackers have found a way around MFA that doesn’t require breaking any encryption or guessing any codes. It just requires you to be tired, distracted, or annoyed enough to tap “Approve.” It’s called MFA prompt bombing (also known as MFA fatigue attacks or push bombing), and it’s become one of the most effective ways to break into accounts protected by push-notification-based authentication.
What Exactly Is MFA Prompt Bombing?
Most modern MFA setups use push notifications instead of one-time codes. You log in, and a notification pops up on your phone asking, “Was this you? Approve or Deny.” It’s fast and convenient — which is exactly what makes it exploitable.
Here’s how the attack works:
- The attacker already has your password. This usually comes from a data breach, phishing attempt, or credential-stuffing attack (reusing leaked passwords from other sites).
- They attempt to log in repeatedly, which triggers a flood of MFA push notifications to your phone — sometimes dozens within a few minutes, sometimes spread out over hours or days.
- They wait for fatigue to set in. Eventually, many people tap “Approve” just to make the notifications stop, assuming it’s a glitch, or without really thinking about what they’re approving.
- The attacker is in.
One accidental tap by your hand allows access to your account, even though your password and MFA were both technically doing their job.
Some attackers take it a step further with social engineering: they’ll call or message the target pretending to be from IT support, saying something like “We’re seeing a security issue, can you approve the verification request we just sent?” This adds a layer of false legitimacy that makes people even more likely to comply.
Here’s Why MFA Prompt Bombing Works
MFA prompt bombing doesn’t exploit a technical flaw — it exploits human psychology.
- Notification fatigue: after the fifth or tenth prompt, people stop reading and just tap to dismiss.
- Assumption of normalcy: people assume a glitch or a delayed login attempt of their own, not an active attack.
- Time pressure and confusion: repeated prompts at odd hours (attackers often target middle-of-the-night windows) catch people half-asleep and less critical.
- Trust in the system: MFA is marketed as a security win, so people don’t expect to be the weak link.
This is why prompt bombing was used in several high-profile breaches, including incidents involving major tech and rideshare companies, where attackers gained initial access simply by wearing down an employee’s patience (and the employees should really know better).
How to Protect Yourself From an Attack
- Never approve a prompt you didn’t trigger
This is the golden rule. If you get an MFA push and you did not just try to log in, the answer is always Deny, not “approve because it’ll probably stop.” Denying it does not lock you out — it protects you. - Treat “IT support” calls about MFA approval with suspicion
Legitimate IT teams do not need you to approve a login on their behalf. If someone contacts you asking you to approve a push notification, verify their identity through a separate, known channel (like calling the official help desk number) before doing anything. - Report repeated unexpected prompts immediately
A sudden flood of MFA requests is a strong signal that your password has already been compromised. Report it to your security or IT team right away, and change your password immediately — even if you never approved anything. - Switch to number-matching or phishing-resistant MFA where possible
Many organizations now support number matching, where you have to type a specific number shown on the login screen into your authenticator app, rather than just tapping “Approve.” This small extra step defeats most prompt bombing because it requires active engagement, not a reflexive tap.- There are several authenticators: Google Authenticator, Microsoft Authenticator, Authy, and those are just to name a few.
Even stronger: FIDO2/WebAuthn security keys (like YubiKeys) or passkeys. These require physical possession of a device and don’t generate spammy push notifications at all — there’s no prompt to bomb.
Always keep your authenticator app and phone secure. An attacker with your password is only halfway there — they still need access to your phone or notification. Keep your device locked, avoid app installs from third parties, and be cautious about app permissions to reduce the chance that an attacker gains device-level access on top of your credentials.
If you work for a large corporation, its IT department generally has strict protocols in place to help keep hackers out. But let me know how you have been keeping your online platforms, bank accounts, and credit card accounts secure. I’m interested to know who is using what technique for additional security.





