The Promise of the Push Notification
For years, security experts have championed Multi-Factor Authentication (MFA) as a critical defense, making you 99% less likely to be hacked. Instead of relying on just a password, MFA requires a second piece of proof that you are who you say you are.
The most popular method became the push notification sent to your smartphone. It seemed like the perfect balance of security and convenience: a simple tap on “Approve” and you were in. This streamlined process was adopted by companies worldwide, from major corporations to universities, to protect everything from email accounts to sensitive internal networks. But attackers quickly realized that this convenience had a hidden, exploitable weakness rooted not in code, but in human psychology.
Weaponizing Annoyance: The 'MFA Fatigue' Attack
This attack, known as “MFA fatigue,” “push bombing,” or “MFA spamming,” is deceptively simple and brutally effective. It begins after an attacker has already obtained your password, often through a phishing scam or by purchasing it off the dark web. With your password in hand, they attempt to log into your account over and over again. Each attempt triggers a push notification to your phone. The first time, you deny it. The fifth time, you might be confused. By the twentieth time—perhaps late at night or during a busy meeting—the constant buzzing becomes a maddening distraction. The attacker is counting on you to approve a request out of sheer frustration, confusion, or the mistaken belief that it's a system glitch. That one tap is all they need to bypass your defenses and gain access.
Why This Method Is So Dangerous
MFA fatigue exploits human nature. It's a social engineering tactic disguised as a technical one. High-profile breaches at major companies like Uber have demonstrated just how successful this method can be. In some cases, attackers combine the notification flood with a phone call, posing as IT support and instructing the target to approve the request to “fix a problem.” An unexpected MFA prompt is more than just an annoyance; it’s a critical security alert. It means an attacker already possesses your password and is actively trying to breach your account. Ignoring this signal or approving the request hands them the keys to your digital life, potentially leading to data theft, financial loss, or a wider corporate network compromise.
Your Defense: From Annoyance to Action
Protecting yourself requires shifting your mindset from passive approval to active defense. The single most important rule is to never, ever approve a login request you did not personally initiate. If you are being spammed with fraudulent requests, the first thing you should do is deny them. The next immediate step is to change the password for that account, which will stop the attacker from being able to trigger more prompts. Report the incident to your IT or security department right away; they can monitor for further suspicious activity. Finally, if your service provider allows it, enable stronger forms of MFA. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recommends methods like “number matching,” which requires you to enter a specific number displayed on the login screen into your authenticator app. This makes it impossible to approve a login by accident.
Beyond the User: What Companies Must Do
While user vigilance is crucial, the ultimate responsibility lies with organizations to build more resilient systems. Blaming a fatigued user for a breach is an outdated approach. Security leaders should prioritize implementing phishing-resistant MFA, such as FIDO2 security keys or biometrics. Where that's not possible, enforcing number matching should be the default setting, as it is a strong mitigation against push bombing. Companies can also configure their systems to limit the number of authentication requests allowed in a short period and to flag repeated, denied logins as a security incident requiring investigation. By adding these layers, companies can move beyond simply asking users to “Approve or Deny” and build a system that is secure by design.













