Independent guide. login.com is an independent educational resource. We are not affiliated with, endorsed by, or connected to the services described. Always sign in only on the service's own official website.
Last reviewed: 2026-08-20 · Report a change
Short answer
What to know before you start
MFA fatigue, or push bombing, happens when an attacker sends repeated approval requests hoping the user will accept one. Never approve a prompt you did not start, even if the numbers match or the alerts become disruptive. Open the service independently, change the exposed password, end sessions, review registered methods, and report the incident to the organization.
01 · decision point
Treat repeated prompts as evidence the first factor may be known
A push request normally follows a sign-in attempt. When prompts arrive without an action you started, someone may already know the username and password or may be testing another active session. CISA describes push bombing as repeated notifications intended to cause an accidental or frustrated approval. Silencing the phone stops the interruption but does not remove the attacker's knowledge or invalidate a session they may already control.
Capture the time, service name, displayed location, device, and any number shown without sharing a live code. Deny the request if the interface offers that choice, then stop interacting with the notification. Do not accept a follow-up call claiming to be the help desk. An attacker can create the prompts and call immediately to make the activity look like a coordinated support process.
02 · decision point
Contain the account from an independently opened route
Use a trusted device or known bookmark to open the real service. Change a reused password, inspect recent sessions, sign out unfamiliar devices, and review registered phones, authenticators, security keys, passkeys, recovery email, and forwarding rules. For a work or school account, contact the authorized security or identity team through a known internal channel. Administrators may have logs and revocation controls the user cannot access.
Start with the identity that can reset other accounts: primary email, password manager, single sign-on, and administrator accounts. If the same password was reused, replace it everywhere with unique values. Preserve evidence before removing unfamiliar methods when the organization may need an investigation. A successful denial means that one request failed; it does not prove the password remains private or that another prompt will not follow.
03 · decision point
Understand what number matching changes
Number matching requires the user to enter or select a value shown in the sign-in session, which makes blind approval harder. Microsoft's current Entra documentation describes it as a security improvement for Authenticator push notifications and says it is enabled for those notifications. CISA recommends number matching when an organization cannot yet implement phishing-resistant MFA. These controls reduce accidental approvals but remain dependent on user intent and the integrity of the sign-in context.
A convincing fake page can relay a legitimate sign-in and show the same number, so matching does not create the domain binding of a passkey or FIDO security key. Always ask whether you initiated the sign-in and whether the browser is on the verified service. If no action was started, reject the request regardless of location accuracy, familiar device name, help-desk story, or matching digits.
04 · decision point
Move high-impact accounts toward phishing-resistant methods
Passkeys and FIDO security keys are bound to the legitimate relying-party domain, which can prevent a copied page from using the credential for another site. Register at least two independent authenticators where supported, and keep recovery codes in protected offline storage. Avoid making one phone the only holder of push approvals, synced passkeys, email, and recovery messages for the same critical account.
Organizations should combine stronger methods with rate limits, risky-sign-in detection, user reporting, and a rehearsed response process. Training alone cannot compensate for an endless approval stream. Users need a clear way to report fraud, administrators need authority to revoke sessions and methods, and incident notes should record whether the password, recovery channel, or device was also compromised.
Practical sequence
Respond to an unexpected approval request
- 01
Deny the prompt and do not engage with a caller or message that references it.
- 02
Record non-secret details such as time, service, location, and device label.
- 03
Open the real service independently and replace the password from a trusted device.
- 04
End unfamiliar sessions and review every registered authentication and recovery method.
- 05
Report a managed account through the organization's known security channel.
- 06
Register a phishing-resistant method and an independent backup after containment.
Original research element
Triage the prompt by what happened before it
This original response matrix separates normal friction from an active credential incident.
| Situation | Immediate action | Likely exposure | Next control |
|---|---|---|---|
| You started the sign-in | Verify domain and matching context | Normal authentication | Complete only the intended request |
| One unexpected prompt | Deny and investigate | Password or session may be exposed | Change password and review methods |
| Repeated prompts or call | Stop interacting and report | Active social-engineering attempt | Revoke sessions and alert security |
| Accidental approval | Treat as compromise | Attacker may have a session | Immediate revocation and incident response |
Common questions
MFA fatigue and push bombing FAQ
What is MFA fatigue?
It is a social-engineering attack that sends repeated authentication prompts in the hope that a person approves one accidentally, from frustration, or after a deceptive support call.
Should I approve a request so the notifications stop?
No. An approval can grant the attacker access. Deny the request, open the service independently, change the exposed password, and review sessions and authentication methods.
Does number matching completely stop push bombing?
It makes blind approval harder, but a relayed fake sign-in can still manipulate the user. Confirm that you initiated the request and use phishing-resistant MFA where possible.
What if I already approved the prompt?
Act immediately: revoke sessions, replace the password, remove unfamiliar methods, secure recovery channels, and report the incident to the organization or provider through a trusted route.
Continue on login.com
Related independent guidance
Primary-source ledger
Official documentation reviewed
Features, plan packaging, interfaces, and recovery controls can change. Every factual product claim on this page is bounded by the official source and checked date below. Recheck the provider documentation before a migration, purchase, administrator change, or high-impact recovery.
- CISA: Implementing number matching in MFA applications ↗Checked 2026-08-20
- Microsoft Entra: how number matching works ↗Checked 2026-08-20
- NIST SP 800-63B-4: authenticator requirements ↗Checked 2026-08-20