Your phone asks you to approve a sign-in you did not start. What should you do?
One unexpected MFA prompt could be a mistake; a stream of them may be an attempt to wear you down. The right response is simple and non-technical.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 3 September 2026
- READING TIME
- 7 min read
- TOPIC
- Identity and Access
Your phone asks, “Approve sign-in?”—but you are not signing in to email or a company system. A second prompt appears, then a third. It is tempting to assume the app is broken and press approve just to make the interruptions stop.
That is exactly what an attacker may be waiting for. A stream of approval requests is often called MFA fatigue or push bombing. CISA describes the technique as repeated mobile notifications intended to make a user approve one accidentally or out of annoyance.
The shortest safe response
If you did not start the sign-in:
- Deny the request. Do not approve it simply to dismiss it.
- Report it to your IT or security team through a phone number or mailbox you already know. Do not follow instructions from a caller who appears moments later and claims they need to “finish an update”.
- Change your password through the official site or app, particularly if the prompts continue. If that password was reused, replace it with a different one on the other accounts too.
- Review recent sign-ins and active sessions if the service provides this view. Sign out devices you do not recognise.
- Never give anybody a one-time code or the number on your screen. Support staff do not need it to “cancel the attack”.
A single stray prompt could result from somebody’s typing error. It should still be denied. Repeated prompts, or a call accompanying them, make an urgent report especially important.
Why “be careful” is not enough
During a working day, people approve legitimate sign-ins to many services. An app that offers only two buttons asks for a decision with little context. Fatigue and repetition favour the attacker.
Organisations should therefore reduce the opportunity for error. Microsoft explains number matching: the sign-in screen displays a number that the user must enter in the authenticator app. Someone who cannot see a sign-in screen they initiated does not have a valid number to copy. Microsoft also identifies number matching as protection against accidental approvals and MFA-fatigue attacks.
Phishing-resistant methods such as security keys and properly deployed passkeys can provide stronger protection. They do not remove the need for a clear reporting route. An employee must know where to raise an unexpected prompt before a convincing “technician” calls them.
If you already pressed approve
Do not wait and do not hide the mistake. Report it immediately, including the approximate time and service name. From a trusted device, change the password, close unfamiliar sessions and check whether recovery details, email-forwarding rules or authentication settings were changed. In a company environment, the team responsible for the account should take over the wider investigation.
An early report may allow an active session to be stopped. Punishing the mistake has the opposite effect: next time, a colleague may spend precious minutes deciding whether silence feels safer.
Source facts and Breachroad’s conclusion
The description of repeated prompts and the recommendation to use number matching come from CISA and Microsoft. The deny-report-protect sequence is Breachroad’s practical response to that scenario.
Our conclusion is that security should not depend on perfect human concentration. The sign-in method should give people context, and the organisation should give them a simple reporting path. Our guide to rolling out MFA in an organisation covers the broader implementation choices. Cybersecurity training for employees turns “do not click” into a concrete response to a real prompt and follow-up call.


