How to train staff to spot MFA fatigue push-bombing attacks

Train staff to spot MFA fatigue push-bombing attacks in 2026: one drilled rule, three drills, and a 30-day plan that stops approval-prompt attacks.

An MFA fatigue attack floods your phone with multi-factor approval prompts until one exhausted tap lets a criminal into your work accounts. The fix is a single drilled reflex — never approve a sign-in prompt you did not personally trigger — plus a reporting habit that catches the attack on attempt one instead of attempt fifteen.

TL;DR

Why this matters

Password theft is cheap in 2026. The same phishing kits that harvest credentials — the kind covered in anti-phishing training — feed straight into MFA fatigue attacks, because almost every business now guards its logins with an approval prompt. The Australian Cyber Security Centre urges everyone to switch multi-factor authentication on and lock accounts down (see its MFA guidance). Attackers adapted in parallel: instead of breaking the second factor, they wait for you to approve it for them.

The attack works on simple arithmetic. An attacker holding a valid username and password triggers a sign-in. Your phone buzzes. You silence it. It buzzes again. Late at night, on the fourth or fifth prompt, approving feels like the only way to make it stop — and one tap later the attacker is reading your mail.

What a push-bombing attack actually looks like

The sequence repeats consistently enough to rehearse:

  1. The attacker obtains a real username and password, usually from a phishing page or an infostealer infection on a personal device.
  2. They attempt a sign-in, which fires an approval prompt to your phone.
  3. You deny it — or ignore it. The attack rarely stops there.
  4. They re-trigger the login again and again. Notifications stack up one after another.
  5. A call or message often follows, impersonating IT: we're testing single sign-on tonight, please approve the prompt.
  6. One approval and the attacker is inside, reading email and resetting whatever they like.

Two details make this dangerous. The prompts look identical to your legitimate sign-ins — same app, same logo, same wording. And the follow-up call reframes the flood as a glitch the employee can fix, which is exactly the reassurance a tired person wants at 11pm.

The one rule to drill

If you did not tap sign in, you never tap approve. Not for IT, not for a manager, not just this once to stop the buzzing.

The rule only holds if staff also know what to do instead of approving: deny the prompt, then report it. A prompt that gets denied quietly is a near-miss nobody learns from. A prompt that gets reported is a signal your IT team can act on — force a password reset, hunt for the phishing page that harvested the password, and warn the rest of the team while the attacker is still outside.

Make the report the documented expectation from day one. The phrase that works in briefings is simple: denying is half the job; reporting is the other half.

Three drills that build the reflex

Drill 1: the unexpected prompt

Send a simulated approval prompt outside any scheduled activity. The learning happens in the debrief: anyone who approves sees exactly what an attacker would have gained, and anyone who denies has their instinct confirmed. Short scenario-based lessons like those in Cyber Aware's security awareness training fit this drill because the whole cycle — simulation, lesson, re-test — takes minutes rather than an afternoon.

Drill 2: the follow-up call

The phone call is where most real approvals happen. After a simulated notification flood, have a help desk caller claim the prompts were a system test and ask the employee to approve. Staff should treat any request to approve a prompt they did not trigger as hostile, no matter who is calling, and hang up rather than negotiate. Rehearse the sentence: I don't approve prompts I didn't start. If this is genuine, raise a ticket.

Drill 3: report-first

Measure who reports, not only who approves. A team with a low approval rate and a zero report rate has learned to deny quietly — the next attack still arrives unannounced. Track report rates alongside click and approval rates; Cyber Aware's human risk reporting shows how report behaviour gets measured team by team instead of as one company-wide score.

Reduce the payoff in the tooling

Training is the core defence, but two settings shrink the attack window around it:

Run a security gap assessment before changing anything, so you know which teams already approve prompts fastest and where the drills will earn their keep first.

A 30-day rollout

Common mistakes

FAQ

What is an MFA fatigue attack? An attacker who already has your username and password spams your phone with sign-in approval prompts until you approve one to make the noise stop. A single approval transfers control of the account.

Why do employees approve the fifteenth prompt? Because the attack usually includes a follow-up: a caller claiming to be IT says the prompts are a test and approval is expected. Tired, relieved that someone explained the buzzing, people approve.

How can I tell if a prompt is real? You don't verify prompts — you match them to your own actions. If you didn't just try to sign in, the prompt is hostile by definition, however authentic it looks.

Does number matching stop push-bombing? It blunts it. Typing a displayed number into the app means the attacker cannot simply wait for a tap, so floods stop working. Pair it with training, because attackers shift to the follow-up call.

What should staff do after denying a prompt? Report it immediately through your security channel or the report button in your training platform. A denied-but-unreported prompt hides an active attack from the people who can shut it down.

How often should we run these drills? Quarterly. Each drill takes minutes, and the report-rate data from each cycle tells you exactly which teams need the next one most.

One last thing

The attacker's decisive weapon is not the notification — it's the plausible phone call afterwards. Rehearse the call, not just the prompt, and you harden staff against every MFA attack variant at once.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.