MFA Fatigue Attacks: When Attackers Push Until Someone Taps Approve
Once a password is stolen, attackers flood a phone with approval prompts until someone taps yes. Here is how number matching, better methods, and training stop it.
Multi-factor authentication is one of the best defenses a small business can deploy, and attackers know it. So instead of trying to defeat it, they wear it down. Once they have stolen a valid password, they trigger approval prompt after approval prompt, betting that a busy or confused user will eventually tap approve just to make the buzzing stop.
This is an MFA fatigue attack, sometimes called push bombing. It does not break your security. It exploits the moment a person stops paying attention.
How push bombing works
The attack has two stages. First the criminal obtains a working password, usually through a phishing page, a reused credential from another breach, or a leaked list. A password alone should not be enough, and that is exactly what MFA is for. So they move to the second stage and attack the second factor directly.
They repeatedly attempt to sign in, and each attempt sends a fresh approval request to the real user's phone. The prompts arrive late at night, during meetings, or in a steady stream that feels like a glitch. Sooner or later, someone approves one to end the annoyance, and the attacker is in.
Number matching removes the easy tap
The simplest improvement is to stop letting people approve with a single reflexive tap. Number matching shows a code on the sign-in screen that the user must type into the approval prompt. If they are not actively signing in, there is no number to enter, and the fatigue attack has nothing to work with.
It is a small change that turns a passive yes into a deliberate action, and it defeats the core trick of push bombing.
Move toward phishing-resistant methods
Stronger authentication methods raise the bar further by removing the approval prompt that fatigue attacks depend on. Where you can, adopt methods that tie sign-in to the device and the person rather than a simple push notification.
- Turn on number matching for every push-based approval as a baseline.
- Prioritize phishing-resistant options such as passkeys and hardware security keys, starting with administrators.
- Retire weaker factors like SMS codes for high-value accounts wherever practical.
- Protect privileged and finance accounts first, since they are the highest-value targets.
Train people to treat prompts as signals
Technology handles part of the problem, but the human response matters just as much. Staff need to understand one clear rule: an approval prompt you did not personally trigger is not a nuisance to clear, it is a warning that someone has your password.
Teach your team to deny unexpected prompts, change the affected password, and report the event immediately. Make reporting easy and blame-free, so people raise their hand the moment something looks wrong instead of hoping it stops on its own.
Use conditional access to cut the noise
You can also reduce how often prompts appear at all. Conditional access lets you trust known, compliant devices and healthy locations, so people are not challenged constantly during normal work. Fewer routine prompts means an unexpected one stands out immediately, which makes both your users and your defenses sharper.
What to do next
Start by enabling number matching across the board this week, since it is quick and high-impact. Then plan a phased move to phishing-resistant methods for admins and finance, add conditional access to reduce unnecessary prompts, and give staff a short, memorable rule for handling unexpected requests.
MFA fatigue attacks succeed only when a person is worn down into agreeing. Remove the reflexive tap, strengthen the method, and train the instinct, and the attack has nowhere to go. A managed services partner can help you sequence this work if you would rather not tune it alone.