MFA fatigue weaponises repetition
If your phone can be made to ask "was this you?" over and over, eventually somebody taps yes.
That is the whole attack. An attacker with a stolen password triggers the approval prompt again and again, often in the middle of the night, until the person accepts it to make it stop, or taps it half-asleep by reflex. Nothing has been broken. The defence is to stop using a prompt that only needs a tap: number matching, where you have to read a code off the screen you are logging in on, removes the reflex the attack depends on.
More on Human factors
- Phishing exploits context, not stupidityIt fitted the gap
- A warning ignored every day stops being a warningThe bell nobody hears
- Security friction moves behaviour elsewhereSqueeze it here, it comes out there
- Verify suspicious requests through a separate channelRing back on a line they never gave you
- People need a safe way to report mistakes quicklyThe shortest road back
- Security training decays without practiceWhat you knew in March
