Cyber Safety · 55 sec
An Unexpected MFA Prompt May Be an Attack
Repeated approval requests can be designed to wear down your attention.
The useful idea
- Push bombing
In an MFA-fatigue attack, someone sends repeated login prompts until the account owner approves one by accident or annoyance.
- The prompt is evidence
An approval request you did not initiate can mean someone already has the password and is attempting the second step.
- Never approve to silence
Deny the request, change the password through the real service, and report repeated prompts to the account provider or workplace.
Why this matters
MFA protects the account only when approval remains a deliberate confirmation of a login you actually started.
Try this
Treat every unrequested MFA prompt as a security alert, not as a notification to dismiss by approving.
Test your recall
Which action best applies “An Unexpected MFA Prompt May Be an Attack”?
- Treat every unrequested MFA prompt as a security alert, not as a notification to dismiss by approving. — correct
- Treat the most familiar option as automatically safest.
- Ignore the mechanism and rely on the first visible result.
MFA protects the account only when approval remains a deliberate confirmation of a login you actually started.