MFA Fatigue: Why We Approve Prompts We Shouldn’t

Getting locked out of an account is frustrating. Getting bombarded with endless login approval requests at two in the morning is worse. In a widely reported 2022 incident, an Uber contractor finally tapped “yes” just to make the notifications stop, and attackers gained full access to the company’s internal systems as a direct result. The technique behind that breach has a name: MFA fatigue, and it’s become one of the most exploited vulnerabilities in modern cybersecurity, precisely because it doesn’t attack the technology at all. It attacks human patience.
What MFA Fatigue Actually Is
Multi-factor authentication has become the standard defense against credential theft, and for good reason: even when an attacker has a working password, most MFA implementations stop them cold at the second verification step. Push-notification-based MFA, where approving a login means simply tapping “yes” on your phone, became popular specifically because it’s fast and convenient compared to typing in a code.
That convenience created a new vulnerability. When attackers already have a valid username and password (obtained through phishing, a data breach, or credential stuffing), they can trigger repeated MFA push notifications to the legitimate user’s device, sometimes dozens in a row, sometimes timed for the middle of the night when a groggy, confused user is more likely to tap “approve” just to stop the noise. This is authentication fatigue, or MFA fatigue: exploiting human exhaustion and irritation rather than trying to break the underlying cryptography or bypass the authentication system technically.
Why This Attack Works So Well
Authentication fatigue succeeds because it exploits genuine, predictable psychology rather than a technical flaw, which makes it resistant to purely technical fixes.
Repetition wears down careful judgment. The first unexpected MFA prompt triggers real suspicion. The fifteenth, arriving in a relentless stream, triggers exhaustion and a desire to make it stop. Decision fatigue is a well-documented phenomenon, and attackers running these campaigns are counting on it directly.
Ambiguity creates plausible doubt. A legitimate user genuinely can’t always tell, in the moment, whether a prompt reflects their own forgotten login attempt on another device, a background app behaving unexpectedly, or an actual attack. That uncertainty makes “just approve it and move on” feel like a reasonable response rather than an obviously risky one.
Timing amplifies the effect. Attacks frequently target off-hours, late at night or early morning, when the victim is least alert, least likely to carefully evaluate the situation, and most motivated to silence a disruptive notification and go back to sleep.
The interface itself offers minimal friction. A single tap to approve, designed for user convenience, means the difference between stopping an attack and enabling one comes down to a split-second decision made under exactly the psychological conditions least suited to careful judgment.
The Psychology Behind Why We Click “Yes”
Security notifications are, by design, meant to feel urgent and demand quick action. That design choice, reasonable for genuinely time-sensitive security alerts, becomes a liability when the same urgency gets weaponized against the person receiving it.
Every day, people receive a stream of legitimate security notifications: login confirmations, purchase alerts, delivery updates. This constant background noise trains a kind of notification fatigue even before an attacker gets involved, a learned habit of clearing notifications quickly rather than scrutinizing each one. Attackers running MFA fatigue campaigns are exploiting an already-existing behavioral pattern, not creating a new vulnerability from scratch.
Recognizing this dynamic matters because it reframes the problem correctly. Falling for an MFA fatigue attack isn’t a failure of intelligence or security awareness in the way falling for an obviously fake phishing email might be perceived. It’s a predictable outcome of normal human psychology under a specific, deliberately engineered kind of pressure, which means the fix has to account for that psychology rather than simply blaming the person who eventually tapped approve.
How to Actually Prevent It
Effective defense against authentication fatigue combines individual awareness with organizational and technical controls, since relying purely on individual vigilance under exhausting circumstances isn’t a reliable long-term defense.
Never approve a login request you didn’t just initiate yourself. This is the single most important individual habit. If an MFA prompt arrives and you weren’t actively logging in at that exact moment, deny it, every time, without exception, even if you’re not certain what triggered it.
Treat a sudden flood of prompts as an active security incident, not an annoyance to silence. Multiple unexpected MFA requests in a short window is a strong signal your password has already been compromised. The correct response is changing that password immediately and reporting the activity, not approving a prompt to make it stop.
Organizations should implement number-matching MFA instead of simple approve or deny prompts. Number-matching requires the user to enter a specific number displayed on the login screen into the authentication app, a small extra step that breaks the “just tap yes” reflex and forces a moment of genuine engagement with what’s actually being approved.
Rate-limit authentication attempts at the organizational level. Technical controls that detect and throttle unusual volumes of MFA requests to a single account can stop an attack before it reaches the point of exhausting the user at all, removing the human vulnerability from the equation entirely.
Build a fast, low-friction reporting path for suspicious authentication activity. Employees who notice unusual MFA prompts need a quick, genuinely easy way to report it without friction or fear of overreacting. A security team that hears about this pattern early can lock down a compromised account before an exhausted employee eventually approves a malicious request.
Train specifically on this attack pattern, not just generic phishing awareness. Most security awareness training still focuses heavily on spotting phishing emails. Authentication fatigue is a distinct technique that deserves its own explicit coverage, since the warning signs and the correct response differ meaningfully from a typical phishing scenario.
The Bottom Line
MFA fatigue attacks succeed by turning one of the most effective account protections available, multi-factor authentication itself, into an exploitable weakness through sheer repetition and psychological pressure. The defense isn’t abandoning MFA; push-based MFA still stops the vast majority of credential-theft attacks that don’t involve this specific, deliberate exhaustion tactic. The defense is recognizing that a flood of unexpected prompts is itself the attack, treating it as an active incident rather than an annoyance, and building organizational controls, like number-matching and rate limiting, that don’t depend entirely on an exhausted human making a perfect decision at two in the morning.
Enjoyed this article?
Subscribe to Professor Simon's weekly newsletter for practical insights, career guidance, and leadership lessons delivered every Friday.
A confirmation email will be sent. If you don't receive it, please check your spam or junk folder.
No spam. Unsubscribe anytime.
Prefer to Listen?
Listen to Professor Simon’s IT & Cybersecurity Podcast for practical conversations about cybersecurity careers, certifications, security leadership, and real-world lessons from the field.
Listen on Spotify