Catching Push-Bombing and MFA-Fatigue Attacks on Your Accounts

Push-bombing—also called MFA-fatigue—is when an attacker floods your phone or device with multi-factor authentication prompts, hoping you’ll approve one out of annoyance or confusion. It’s effective because many services use “tap to approve” push notifications, and people are used to quickly accepting them. This guide explains how these attacks work, the warning signs, and the practical steps you can take to block them and keep your accounts safe.

What Is Push-Bombing (MFA-Fatigue)?

Multi-factor authentication (MFA) adds an extra step to logins, typically via a code, a prompt, or a hardware key. In a push-based system, you receive a notification to approve or deny a login. Attackers who already have your username and password—often from a data breach, password reuse, or phishing—try to log in repeatedly, triggering a stream of prompts. If you approve once, they’re in.

  • Why it works: Habit, distraction, and trust in familiar prompts.
  • What attackers need: Your password first, then persistence. They may also spoof caller ID, send emails, or message you pretending to be “IT” to persuade you to approve.
  • Common targets: Email accounts, cloud storage, workplace single sign-on (SSO), banking, and social media.

Red Flags That You’re Being Targeted

  • Unexpected prompts: You’re not trying to log in, but you get one or more approval requests.
  • Prompt storms: Multiple MFA prompts in quick succession, at odd hours, or over several days.
  • Pressure messages: A text, email, or call claiming to be support or security staff urging you to “approve to stop the alerts” or “verify identity.”
  • Location mismatch: Push prompt shows a device or location you don’t recognize.
  • Account alerts: New device sign-in alerts, password reset emails you didn’t initiate, or unfamiliar “new session” notices.

Immediate Actions If You Receive Surprise MFA Prompts

  1. Do not approve. Tap Deny or No. If there’s an option to report “Not me,” use it.
  2. Change your password for the affected account immediately from a device you trust. Generate a unique, long password with a password manager.
  3. End active sessions. In the account’s security settings, sign out of all devices and revoke unrecognized sessions or app tokens.
  4. Rotate backup codes. If the service offers backup codes, regenerate them and store securely.
  5. Switch your MFA method to a phishing-resistant option (details below) if available.
  6. Enable additional alerts such as new-device or new-location sign-in notifications.

How Attackers Get Your Password in the First Place

  • Data breaches and password reuse: Reusing the same password across sites allows credential stuffing attacks.
  • Phishing: Fake login pages harvest your credentials, then attackers immediately attempt login with push spam.
  • Malware and infostealers: Compromised devices and browsers leak saved passwords.
  • SIM swap and phone takeover: Less common for push-only MFA, but often paired with text-based codes and account recovery attacks.

Choose Stronger MFA That Resists Push-Bombing

Not all MFA is equal. Prioritize methods that require a code tied to your device or a hardware challenge the attacker can’t trigger repeatedly.

  • Best options (where supported):
    • Security keys (FIDO2/WebAuthn): A physical key (e.g., USB/NFC) you tap to approve. Resistant to phishing and push-spam.
    • Platform passkeys: Built-in device-based authentication using biometrics or device PIN, synced securely across your ecosystem.
    • Authenticator app codes (TOTP): Time-based one-time codes in apps like Aegis, Authy, or Microsoft/Google Authenticator. No push to spam.
  • Acceptable with caution: Number-matching or PIN-in-prompt push. These require you to enter or confirm digits shown on the login screen, reducing accidental approvals.
  • Avoid when possible: SMS or email codes (vulnerable to SIM swap and mailbox compromise) and simple “tap to approve” push without number matching.

Lock Down Your Accounts Step by Step

  1. Inventory critical accounts: Email, cloud storage, banking, payroll, tax, password manager, social media, ecommerce, and any account that can reset others.
  2. Use unique, long passwords: Aim for 14–20+ characters generated by a password manager. Never reuse passwords.
  3. Enable phishing-resistant MFA: Prefer security keys or passkeys; otherwise use authenticator apps. Turn off basic push approvals if you can switch to number matching or TOTP.
  4. Review trusted devices and sessions: Remove any device or OAuth/app connection you don’t recognize.
  5. Harden recovery options: Add a secure recovery email, keep recovery codes offline, and disable insecure recovery methods where possible.
  6. Set granular alerts: Turn on new-login, new-device, password change, and recovery change notifications.

Stopping an Ongoing MFA-Fatigue Attack

  • Silence without approving: Disable notifications temporarily on your phone so you’re not tempted to tap “Approve.” Only deny if your app lets you mark it as fraudulent.
  • Change password from another device: Use a separate, trusted device or a different network to sign in and reset credentials.
  • Force-log out sessions: Use “Sign out all sessions” or “Revoke tokens” features in security settings.
  • Escalate MFA: Immediately switch to TOTP, passkeys, or security keys; remove simple push approvals.
  • Check email rules and forwards: Attackers often set hidden forwarding rules to catch password-reset emails.
  • Check connected apps: Remove unfamiliar API tokens or third-party app connections that may bypass prompts.

Extra Protections That Reduce Risk

  • Password manager hygiene: Enable MFA on your password manager and lock it on all devices. Review vault shares and emergency access.
  • Device security: Update your OS and apps, enable full-disk encryption, and use screen locks and biometric unlock.
  • Browser hardening: Update browsers, restrict extensions, clear unused saved logins, and enable safe browsing features.
  • Phishing resistance training: Verify URLs, beware of lookalike domains, and never approve a prompt because someone “from support” told you to.
  • Phone number hygiene: Remove phone numbers as recovery methods where alternatives exist. Set a carrier account PIN and a port-freeze to reduce SIM-swap risk.

What to Do If You Approved a Prompt by Mistake

  1. Act fast: Change the account password, revoke sessions, and rotate backup codes immediately.
  2. Audit changes: Look for newly added recovery emails, phone numbers, or security keys you did not add.
  3. Check for data access: Review login history, file access logs, and any outgoing messages or posts from your account.
  4. Scan your devices: Run reputable antivirus/antimalware on your primary devices to rule out malware or infostealers.
  5. Monitor for follow-on fraud: Watch for password reset attempts or new-account signups tied to your email.

When and How to Get Help

  • Service provider support: Many platforms have “compromised account” workflows that escalate recovery and lock attackers out.
  • Workplace/School IT: Report the incident so they can enforce number matching, block the attacker’s IP/device, and review access logs.
  • Financial and identity monitoring: If any financial or high-impact account was exposed, set fraud alerts, watch for suspicious credit activity, and consider credit monitoring and identity alerts to catch misuse early. A dedicated resource like SmartCredit for privacy, credit monitoring, and identity protection can help you detect changes that may indicate account takeover or identity fraud.

Configure Popular MFA Systems to Reduce Fatigue Attacks

Settings vary by provider, but look for these options in your security dashboard and prioritize them in order:

  1. Enable number matching (if using push). You must enter digits from the login screen, blocking blind approvals.
  2. Require device biometrics for approvals, such as Face ID or a fingerprint.
  3. Limit approval frequency by enabling session persistence for trusted devices you control, reducing daily prompts without weakening security.
  4. Use TOTP or passkeys instead of tap-to-approve push prompts when available.
  5. Turn off SMS fallback unless it’s your only recovery method; prefer backup codes kept offline.

Build Habits That Catch Attacks Early

  • Two-beat check: Any prompt you weren’t expecting is a red flag. Ask yourself: “Am I logging in right now? Does the location/device make sense?”
  • Don’t rush approvals: Slow down and read the prompt details before tapping.
  • Calendar your security: Monthly, review active sessions, connected apps, recovery methods, and recent login history for your top accounts.
  • Segment accounts and emails: Use separate email addresses for banking, shopping, and social; this limits blast-radius if one account is compromised.
  • Practice incident drills: Know where the “Sign out all sessions,” “Devices,” and “Security Keys” settings live for your major accounts.

Frequently Asked Questions

Is push-based MFA safe to use?

It’s safer than no MFA, but basic tap-to-approve prompts can be manipulated with push-bombing. Upgrading to number-matching push, TOTP codes, passkeys, or security keys significantly improves protection.

What if my account doesn’t support passkeys or security keys?

Use an authenticator app for TOTP codes and enable number-matching push if available. Disable SMS where you can and secure recovery options with strong, unique passwords and backup codes.

Why do I get prompts late at night?

Attackers try off-hours when you’re tired and more likely to approve out of habit. Decline, change your password, and revoke sessions.

Can attackers bypass MFA entirely?

Some advanced phishing tools can relay logins in real time. Phishing-resistant methods like security keys and modern passkeys are designed to prevent these relays by binding authentication to the genuine site.

Should I remove all push MFA?

No. Replace simple push with number matching or biometrics when possible, or switch to TOTP/passkeys. The goal is to keep MFA strong while eliminating easy-to-spam approval methods.

Conclusion

Push-bombing works by turning your own habits against you. Treat any unexpected prompt as an attempted break-in, deny it, and immediately reset your password and sessions. Upgrading to phishing-resistant MFA—security keys, passkeys, or TOTP—shuts down most fatigue attacks, while regular reviews of devices, connected apps, and recovery settings keep you a step ahead. Combine strong authentication with vigilant monitoring and you’ll make your accounts—and your identity—far harder to exploit.

Good to Know

If you get a surprise MFA prompt and you are not actively logging in, decline it and immediately change your password and session tokens. Attackers often combine password reuse with push spam to trick you during busy moments.