MFA fatigue weaponises repetition

If your phone can be made to ask "was this you?" over and over, eventually somebody taps yes.

That is the whole attack. An attacker with a stolen password triggers the approval prompt again and again, often in the middle of the night, until the person accepts it to make it stop, or taps it half-asleep by reflex. Nothing has been broken. The defence is to stop using a prompt that only needs a tap: number matching, where you have to read a code off the screen you are logging in on, removes the reflex the attack depends on.

More on Human factors