MFA fatigue, also called push bombing, happens when an attacker repeatedly sends sign-in approval notifications to a user’s phone. The attacker hopes the person will tap Approve by mistake, become annoyed, or believe a caller who claims the prompts are part of an IT test.
Why repeated prompts are a serious warning
To generate a valid approval request, the attacker may already know the username and password or have another way to start the login. The MFA prompt may be the last barrier. Approving just one request can give access to email, cloud files, work systems, or accounts that use that email for recovery.
Some attackers follow the notifications with a phone call, chat, or email pretending to be a help-desk employee. They may ask the victim to approve a prompt, read a number, or install remote-access software. Real support staff should not require you to approve a login you did not initiate.
What to do while the prompts are arriving
- Select Deny or report the request as suspicious.
- Do not keep interacting with an unsolicited caller or message.
- Use a different trusted device to open the account’s official security page.
- Change the password to a unique one that is not used elsewhere.
- Sign out unknown sessions and review registered MFA methods.
If the affected account is for work or school, contact the official IT channel immediately. Give the time, account name, device type, and prompt location after removing unnecessary personal details. Fast reporting helps administrators review logs and block an active attack.
Review the account for persistence
Check recent sign-ins, devices, recovery email, recovery phone, forwarding rules, app passwords, connected apps, and newly added authenticators. Attackers who gain access may add their own method or create inbox rules to hide warnings.
For email accounts, inspect Sent, Deleted, and forwarding settings. For cloud or social accounts, check sharing changes and active sessions. For banking or e-wallet accounts, call the institution through the number in the official app, website, or card if any financial information may be exposed.
Use stronger MFA where available
CISA recommends phishing-resistant MFA such as FIDO/WebAuthn security keys or passkeys where supported. These methods bind approval to the legitimate service and reduce the chance that a fake page or push request can be accepted.
If push approval is the only practical option, number matching is a stronger interim control than a simple Approve button. The phone displays a challenge and the user must match a number from the login screen. It does not make phishing impossible, but it reduces accidental approval of blind prompts.
Change reused passwords in the right order
Start with the primary email account, then financial accounts, work systems, password manager, social media, shopping, and other services that reused the exposed password. Use unique passwords and store them in a reputable password manager. Our guide to creating a strong password explains why adding one symbol to an old reused password is not enough.
Do not turn MFA off simply to stop the prompts. That removes the barrier the attacker is trying to cross. Secure the password and sessions first, then change the MFA method through the official account settings.
How to verify that the attack is contained
- Confirm the new password works only on your trusted device.
- Check that all unfamiliar sessions are gone.
- Verify recovery contacts and MFA methods.
- Review security logs again after several hours.
- Watch for password-reset or financial alerts on related accounts.
If prompts continue after the password change, the attacker may have an active session, connected app, or another recovery route. Escalate to the provider or administrator instead of repeatedly changing settings without a record.
Philippines-specific response
Unexpected prompts may be paired with calls claiming to represent a bank, e-wallet, telco, school, BPO employer, or government office. End the call and dial the organisation’s published number yourself. Never share an OTP, MPIN, authenticator code, recovery code, or screen through chat.
When to get official help
Contact the account provider or workplace administrator when you cannot revoke a session, recovery details changed, or an approval was accidentally accepted. Notify banks and e-wallets immediately if the account can reset financial access. Preserve screenshots and Asia/Manila timestamps, but redact codes before sharing them with support.
Checked against current CISA MFA and number-matching guidance on August 30, 2026. Available authentication methods vary by provider and organisation.



