What Is MFA Fatigue and How to Stop It

What is MFA fatigue

Your phone buzzes at midnight with a login approval request you did not start. Then another, and another. That is not a glitch — it is an attack called MFA fatigue, and it is designed to wear you down until you tap “approve.” Our GetMyPassword team explains what MFA fatigue is, why it works, and how to shut it down.

What MFA fatigue is
What MFA fatigue is and how to defend against it.

What MFA fatigue is

MFA fatigue, also called push bombing, is when an attacker who already has your password floods you with two-factor approval requests. Every “Was this you? Approve or Deny” notification is another chance for you to tap the wrong button. The attacker is betting that, out of confusion or sheer annoyance, you will eventually approve one — and that single tap lets them in.

Why it works

The trick preys on habit and irritation. People approve the prompt to make the buzzing stop, assume it is a system error, or tap “approve” on autopilot without reading it. Sometimes the attacker pairs it with a fake call or message pretending to be IT support, “confirming” that you should approve. The weak point is not the technology — it is the moment of impatience.

How to defend against it

  • Never approve a request you did not start — if you were not logging in, always deny.
  • Treat a flood of prompts as a warning that your password is already known.
  • Prefer number-matching or code-based 2FA over one-tap approvals where offered.
  • Use an authenticator app or hardware key, which require you to act, not just tap yes.

An approval prompt you did not trigger is not a nuisance to dismiss — it is proof that someone already has your password. The right response is to deny every one and change that password at once.

If it happens, change your password

Unexpected approval requests mean one thing: your password has leaked. Deny them all, then immediately change that password to a long, unique one from our password generator and review the account’s security settings. Strong two-factor authentication only protects you if the password behind it is not already in someone else’s hands.

Frequently asked questions

What is MFA fatigue?

It is an attack where someone who already has your password floods you with two-factor approval requests, hoping you tap “approve” out of confusion or annoyance. Also called push bombing, it relies on one careless tap to grant access.

What should I do if I get login prompts I did not request?

Deny every one, and treat them as proof your password has leaked. Change that password immediately to a strong, unique one, and review your account security. Never approve a request for a login you did not start.

How do I prevent MFA fatigue attacks?

Use number-matching or code-based two-factor authentication instead of one-tap approvals where possible, prefer an authenticator app or hardware key, and never approve a prompt you did not trigger yourself.

Help your friends stay safe. Share this article!