An MFA fatigue attack floods your phone with multi-factor approval prompts until one exhausted tap lets a criminal into your work accounts. The fix is a single drilled reflex — never approve a sign-in prompt you did not personally trigger — plus a reporting habit that catches the attack on attempt one instead of attempt fifteen.
TL;DR
- If a login prompt appears that you did not start, tap Deny and report it — never approve.
- Denial rarely ends the attack: scammers re-send prompts and often follow up with a fake IT support call.
- Train the report as part of the same reflex, and measure report rates, not just approval rates.
- Number matching shrinks the payoff, but staff training carries the defence.
Why this matters
Password theft is cheap in 2026. The same phishing kits that harvest credentials — the kind covered in anti-phishing training — feed straight into MFA fatigue attacks, because almost every business now guards its logins with an approval prompt. The Australian Cyber Security Centre urges everyone to switch multi-factor authentication on and lock accounts down (see its MFA guidance). Attackers adapted in parallel: instead of breaking the second factor, they wait for you to approve it for them.
The attack works on simple arithmetic. An attacker holding a valid username and password triggers a sign-in. Your phone buzzes. You silence it. It buzzes again. Late at night, on the fourth or fifth prompt, approving feels like the only way to make it stop — and one tap later the attacker is reading your mail.
What a push-bombing attack actually looks like
The sequence repeats consistently enough to rehearse:
- The attacker obtains a real username and password, usually from a phishing page or an infostealer infection on a personal device.
- They attempt a sign-in, which fires an approval prompt to your phone.
- You deny it — or ignore it. The attack rarely stops there.
- They re-trigger the login again and again. Notifications stack up one after another.
- A call or message often follows, impersonating IT: we're testing single sign-on tonight, please approve the prompt.
- One approval and the attacker is inside, reading email and resetting whatever they like.
Two details make this dangerous. The prompts look identical to your legitimate sign-ins — same app, same logo, same wording. And the follow-up call reframes the flood as a glitch the employee can fix, which is exactly the reassurance a tired person wants at 11pm.
The one rule to drill
If you did not tap sign in, you never tap approve. Not for IT, not for a manager, not just this once to stop the buzzing.
The rule only holds if staff also know what to do instead of approving: deny the prompt, then report it. A prompt that gets denied quietly is a near-miss nobody learns from. A prompt that gets reported is a signal your IT team can act on — force a password reset, hunt for the phishing page that harvested the password, and warn the rest of the team while the attacker is still outside.
Make the report the documented expectation from day one. The phrase that works in briefings is simple: denying is half the job; reporting is the other half.
Three drills that build the reflex
Drill 1: the unexpected prompt
Send a simulated approval prompt outside any scheduled activity. The learning happens in the debrief: anyone who approves sees exactly what an attacker would have gained, and anyone who denies has their instinct confirmed. Short scenario-based lessons like those in Cyber Aware's security awareness training fit this drill because the whole cycle — simulation, lesson, re-test — takes minutes rather than an afternoon.
Drill 2: the follow-up call
The phone call is where most real approvals happen. After a simulated notification flood, have a help desk caller claim the prompts were a system test and ask the employee to approve. Staff should treat any request to approve a prompt they did not trigger as hostile, no matter who is calling, and hang up rather than negotiate. Rehearse the sentence: I don't approve prompts I didn't start. If this is genuine, raise a ticket.
Drill 3: report-first
Measure who reports, not only who approves. A team with a low approval rate and a zero report rate has learned to deny quietly — the next attack still arrives unannounced. Track report rates alongside click and approval rates; Cyber Aware's human risk reporting shows how report behaviour gets measured team by team instead of as one company-wide score.
Reduce the payoff in the tooling
Training is the core defence, but two settings shrink the attack window around it:
- Number matching. Where your MFA tool supports it, approval requires typing a number displayed on the login screen into the app. An attacker running a flood has no number to enter, so the buzz-buzz-buzz becomes pointless noise they eventually abandon.
- App-based approvals over SMS codes. SMS codes can be intercepted or redirected; authenticator apps keep the approval decision on the employee's own device.
Run a security gap assessment before changing anything, so you know which teams already approve prompts fastest and where the drills will earn their keep first.
A 30-day rollout
- Week 1: brief the one rule in every team meeting. Put deny and report in writing as the expected behaviour.
- Week 2: run drill 1, with a short follow-up lesson for anyone who approves.
- Week 3: run drills 2 and 3 together — the follow-up call plus report-rate measurement.
- Week 4: review report rates by team, re-brief the laggards, and confirm number matching is enabled wherever the tooling supports it.
Common mistakes
- Treating the approver as the whole story. The employee who approved is the end of a chain that started with a stolen password. Fix the phishing exposure as well as the habit.
- Annual training only. The reflex decays between annual sessions. Quarterly drills of a few minutes each hold it in place.
- We have MFA, so we are safe. MFA moved the attack from breaking the factor to borrowing your thumb. Treat approvals as attack surface.
- No reporting channel for phone events. If staff only know how to report suspicious email, push-notification attacks stay invisible.
FAQ
What is an MFA fatigue attack? An attacker who already has your username and password spams your phone with sign-in approval prompts until you approve one to make the noise stop. A single approval transfers control of the account.
Why do employees approve the fifteenth prompt? Because the attack usually includes a follow-up: a caller claiming to be IT says the prompts are a test and approval is expected. Tired, relieved that someone explained the buzzing, people approve.
How can I tell if a prompt is real? You don't verify prompts — you match them to your own actions. If you didn't just try to sign in, the prompt is hostile by definition, however authentic it looks.
Does number matching stop push-bombing? It blunts it. Typing a displayed number into the app means the attacker cannot simply wait for a tap, so floods stop working. Pair it with training, because attackers shift to the follow-up call.
What should staff do after denying a prompt? Report it immediately through your security channel or the report button in your training platform. A denied-but-unreported prompt hides an active attack from the people who can shut it down.
How often should we run these drills? Quarterly. Each drill takes minutes, and the report-rate data from each cycle tells you exactly which teams need the next one most.
One last thing
The attacker's decisive weapon is not the notification — it's the plausible phone call afterwards. Rehearse the call, not just the prompt, and you harden staff against every MFA attack variant at once.