What Should You Do When You Receive an Unexpected Multi-Factor Authentication Prompt?

Multi-factor authentication (MFA) is one of the best defenses against account takeovers, but it also creates a moment you can use to spot an active attack. If you receive an MFA prompt you didn’t initiate—whether it’s a push notification, SMS code, email code, or phone call—assume someone is trying to sign in as you. This guide explains what to do in the moment, how to lock down your accounts afterward, and how to prevent “prompt-bombing” and related attacks in the future.

First Response: What to Do the Moment You See an Unexpected MFA Prompt

  • Do not approve it. Never tap “Yes,” “Allow,” or enter the code if you didn’t start the login. Approving gives an attacker immediate access.
  • Deny and report if your app allows it. Some push apps include “Deny” with a “Report” or “This wasn’t me” option. Use it to flag abuse and potentially lock out the session.
  • Change the account password right away. The attacker likely has your current password. On a trusted device, go to the site directly (do not use links in messages) and change your password to a long, unique passphrase.
  • Sign out of all active sessions. Many services offer “Sign out of all devices” or “Log out everywhere.” Do this immediately after the password change.
  • Review recent activity. Check login history, recent devices, and recovery settings for changes you didn’t make.
  • If the prompts won’t stop, temporarily disable push approvals. Switch the account’s MFA method to an authenticator app with codes or to a hardware key while you reset access. Re-enable push later only if it supports number matching or additional verification.

Why You Got the Prompt: Common Causes

  • Password compromise. Your password may have leaked in a data breach, been reused across sites, or been phished.
  • MFA prompt-bombing (MFA fatigue). Attackers send repeated push requests hoping you’ll accidentally or wearily approve one.
  • Phishing with real-time relays. An attacker tricks you into entering your code on a fake page and relays it to the real service instantly.
  • Malicious extensions or malware. Untrusted browser add-ons or infostealers can capture login details and trigger MFA challenges.
  • SIM swap or number misuse. If your MFA uses SMS or voice, an attacker who takes over your phone number can receive codes.

Immediate Lockdown Checklist (Within 15 Minutes)

  1. Go directly to the account’s official website or app. Do not use links in emails or texts about the prompt.
  2. Change your password. Use a unique passphrase (e.g., four to five random words) stored in a reputable password manager.
  3. Revoke active sessions and trusted devices. Force logouts everywhere.
  4. Rotate backup codes. Generate new backup codes and store them offline.
  5. Harden MFA. Prefer a hardware security key or an authenticator app with number matching over basic push/SMS.
  6. Check recovery options. Verify your recovery email and phone are correct and only yours; remove anything unfamiliar.
  7. Scan your devices. Run security scans on your primary devices to rule out malware or malicious extensions.

Strengthen Your MFA: Better Options and Settings

Not all MFA is equal. Choose methods that resist phishing and prompt-bombing.

  • Best: Hardware security keys (FIDO2/WebAuthn). Phishing-resistant and cannot be approved accidentally. Keep at least two keys and store one safely.
  • Strong: Authenticator apps with number matching. If you use push, enable number matching or verification codes that require entering a number displayed on the login screen.
  • Acceptable: Time-based one-time passwords (TOTP) from an authenticator app. More secure than SMS, but codes can be phished if you enter them on a fake site.
  • Avoid when possible: SMS or voice call codes. Useful as a backup, but vulnerable to SIM swaps and interception.

Reduce the Risk of Future Unexpected Prompts

  • Use a password manager and unique passwords. Unique credentials stop a leak on one site from affecting others.
  • Enable phishing-resistant MFA where supported. Opt for security keys on critical accounts (email, bank, password manager, cloud storage).
  • Turn on additional sign-in safeguards. Features like “require device passcode,” “number matching,” or “biometric confirmation” make push approvals safer.
  • Harden account recovery. Remove old phone numbers, add a secondary email you control, and store backup codes offline.
  • Keep devices and browsers clean. Uninstall extensions you don’t recognize or need, keep software updated, and run reputable security tools.
  • Be skeptical of urgent prompts. Attackers count on panic. If a prompt appears, pause and verify.

How to Tell If It Was a False Alarm

Sometimes, an unexpected prompt has a harmless cause—like a password manager testing credentials or you accidentally tapping a login on another device. Confirm carefully before assuming all is well:

  • Check device activity and login history. If you see an unfamiliar location, device, IP address, or time, treat it as an attack.
  • Consider recent actions. Did you just install a new app, open a saved login page, or try a new email client? These can trigger legitimate attempts.
  • When in doubt, still rotate your password. It’s safer to change it and review settings than to risk an unnoticed breach.

If You Accidentally Approved the Prompt

  1. Disconnect the attacker immediately. From a trusted device, change your password and sign out of all sessions.
  2. Re-secure MFA and recovery. Remove unknown authenticators, regenerate backup codes, and verify recovery contacts.
  3. Review data access. Check for new forwarding rules (email), connected apps, API tokens, filters, payment changes, or security settings the attacker may have planted.
  4. Monitor for downstream abuse. Watch for password reset emails on other accounts, bank alerts, and unusual messages to your contacts.

Watch Out for Related Threats

  • Phishing pages that proxy MFA in real time. Always navigate to sites directly and use a password manager, which won’t autofill on fake domains.
  • SIM swap attempts. Add a port-out/PIN lock with your mobile carrier and minimize reliance on SMS verification.
  • Malicious browser extensions and info-stealing malware. Only install reputable extensions you truly need and audit them regularly.

Priority Accounts to Lock Down First

If you received an unexpected MFA prompt, start with the accounts that, if compromised, could cascade into broader identity or financial harm:

  • Primary email. It’s the recovery hub for many logins and a top target for account takeovers.
  • Financial accounts. Banking, credit cards, investment platforms, payment apps, and tax portals.
  • Password manager. Treat any hint of compromise with urgency and consider rotating vault credentials.
  • Cloud storage and productivity suites. Documents and IDs stored here can fuel identity fraud.
  • Mobile carrier account. Protects against SIM swap and number hijacking.

Step-by-Step: Securing a High-Value Account After an Unexpected Prompt

  1. Change password to a unique passphrase using a password manager.
  2. Upgrade MFA to a hardware key or an authenticator app with number matching.
  3. Rotate backup codes and store them offline.
  4. Remove unknown devices and log out everywhere.
  5. Check forwarding rules, filters, and app passwords (especially on email).
  6. Verify recovery email/phone and add a second trusted method.
  7. Audit connected apps and tokens; revoke anything you don’t recognize.
  8. Enable alerts for new logins, password changes, and recovery updates.

When to Involve Support or Your Carrier

  • Contact the service’s support team if you see repeated login attempts, can’t remove an unknown device, or suspect your recovery methods were changed.
  • Call your mobile carrier if you stop receiving service unexpectedly or see signs of SIM swap. Add a carrier PIN/port freeze and verify no unauthorized changes were made.

Ongoing Monitoring and Identity Protection

After any suspicious sign-in attempt, plan to monitor for spillover effects. Attackers with partial access may try password resets on other services or test saved payment methods. Keep an eye on your email for unfamiliar alerts, your bank and card statements for small “test” charges, and your credit for new-account fraud. If you suspect identity misuse, freeze your credit with all three major bureaus and document any incidents.

If you want a simple way to keep an eye on your financial identity alongside better account hygiene, consider evaluating credit and identity monitoring options as a complement to strong passwords and MFA. One place to start is our overview here: SmartCredit for Privacy, Credit Monitoring, and Identity Protection.

Conclusion

An unexpected MFA prompt is a high-value warning: someone likely has your password and is trying to force their way in. Declining the prompt is not enough. Immediately change your password, sign out all sessions, review recent activity, and upgrade to stronger MFA—ideally security keys or authenticator apps with number matching. Tighten recovery options, remove suspicious extensions, and keep a close watch on your most important accounts, especially primary email and financial services. With quick action and stronger defenses, you can turn a scare into a security upgrade that meaningfully reduces your risk going forward.

Good to Know

An unexpected MFA prompt usually means someone already has your password and is trying to break in; denying the request is not enough—immediately change your password and lock the account down.