MFA Fatigue Attacks: How Businesses Can Stop Push Bombing

If you receive an MFA prompt you did not request, do not approve it.

It may be an MFA fatigue attack, also called push bombing.

This happens when an attacker who has obtained a password repeatedly triggers login approval requests. Their goal is to wear the user down until they tap “Approve” out of habit, frustration, or confusion.

If an MFA notification appears and you did not initiate a login:

  • Do not approve it
  • Deny the request
  • Report it to your IT team immediately
  • Change your password if instructed
  • Review your account activity

Businesses can reduce this risk with number matching, conditional-access rules, prompt limits, employee awareness training, and phishing-resistant authentication methods such as passkeys or security keys for sensitive accounts.

The simple rule for employees: Never approve a sign-in request you did not start.

Reach out to Bernie Orglmeister at support@skyviewtek.com or call 610-590-5006.