June 16, 2026

MFA Fatigue: When Attackers Just Keep Asking

Multifactor authentication remains one of the best security upgrades a business can make. So attackers found a way to abuse the part humans control: the approval prompt.

The technique is called MFA fatigue, and it is blunt. An attacker who has already stolen a password triggers login attempt after login attempt, flooding the real user’s phone with approval requests at all hours. Eventually someone taps approve, whether out of annoyance, confusion, or the hope that it will make the buzzing stop. One tap is all it takes.

How to take the weapon away

  • Switch to number matching. Instead of a bare approve button, the login screen shows a number the user must type into their authenticator. A random 2 AM prompt becomes impossible to approve by accident.
  • Treat unexpected prompts as an alarm. An MFA request you did not trigger means someone has your password right now. That is a report it moment, not an ignore it moment.
  • Limit the retries. Modern identity platforms can lock out repeated MFA attempts and alert on the pattern. Most businesses have this available and turned off.
  • Move toward passkeys where you can. No prompt to spam means no fatigue to exploit.

If your MFA setup still uses plain approve buttons, this is a quick fix with a big payoff. Book a free consultation and we will review your login security in one sitting.

Questions about your own setup?

Let’s Connect