MFA Bombing: When the Codes Won’t Stop
What this means
A flood of login prompts isn’t a glitch — it’s often someone already holding your password and hoping you’ll tap Approve just to make it stop.
Note: This site may show light ads and occasional affiliate links. How that works.
Multi-factor authentication is meant to slow attackers down. MFA bombing (sometimes called prompt fatigue) flips that: you get so many “Approve login?” taps that one tired Approve feels like the only way to get peace.
If someone can trigger those prompts, they may already have your password. The bomb is the second half of the break-in.
Remember this: Never approve an MFA prompt you didn’t start. Silence the noise by securing the account — not by tapping Yes.
1. What it looks like
Phone buzzing every minute. Email full of “new sign-in” warnings. An authenticator app lighting up while you’re watching television. Sometimes a caller pretends to be support and coaches you to “just approve so we can stop the attack.”
That last line is the trap dressed as help.
2. A calm response
- Deny / ignore every prompt you didn’t initiate.
- Change the password from a device and browser you trust — not from a link in a scary email.
- Turn on number-matching or phishing-resistant options where your provider offers them (so a random Approve isn’t enough).
- Sign out other sessions and check recent devices in account settings.
- If work accounts are involved, tell IT even if you feel embarrassed — prompt floods are a known pattern.
3. Why “just approve once” fails
Approving once can hand the attacker a session. They don’t need you to stay in the chat. One tired tap is enough.
Treat unexpected prompts like a smoke alarm: you don’t silence it by opening the door to a stranger; you check the house.
A habit to keep
If prompts arrive and you weren’t logging in, assume the password is burned. Reset it, then clean up sessions.
MFA still helps — especially with number matching or passkeys. The habit is refusing fatigue as a reason to approve.
