InspeticaOpen the daily feed

Cyber Safety · 55 sec

An Unexpected MFA Prompt May Be an Attack

Repeated approval requests can be designed to wear down your attention.

  1. Push bombing

    In an MFA-fatigue attack, someone sends repeated login prompts until the account owner approves one by accident or annoyance.

  2. The prompt is evidence

    An approval request you did not initiate can mean someone already has the password and is attempting the second step.

  3. Never approve to silence

    Deny the request, change the password through the real service, and report repeated prompts to the account provider or workplace.

MFA protects the account only when approval remains a deliberate confirmation of a login you actually started.

Treat every unrequested MFA prompt as a security alert, not as a notification to dismiss by approving.

Test your recall

Which action best applies “An Unexpected MFA Prompt May Be an Attack”?

  • Treat every unrequested MFA prompt as a security alert, not as a notification to dismiss by approving. — correct
  • Treat the most familiar option as automatically safest.
  • Ignore the mechanism and rely on the first visible result.

MFA protects the account only when approval remains a deliberate confirmation of a login you actually started.

EvergreenLast verified 2026-08-02

Sources