Digital Gnome
TECHNOLOGY ASSURANCE

Tell us who you are and we’ll cut the rest

One tool for the whole job, from a locked laptop to a signed policy. Answer two questions and we’ll show you only what fits, priced for your size.

1 · HOW MANY OF YOU?
2 · WHAT DO YOU DO? OPTIONAL
✓ NO CARD NEEDED ✓ FREE FOREVER FOR SMALL TEAMS ✓ BUILT IN WALES
Your business
LIVE PREVIEW
YOUR PLAN
WHAT YOU’D GET
← Back to news
PRACTICAL 24 MAY 2026 · 3 MIN

Multi-factor fatigue: why one unexpected prompt matters

If your phone asks you to approve a sign-in you did not start, that is not a glitch. It means your password is already in someone else's hands.

FFION DAVIES · SUPPORT LEAD
SHARE LinkedIn X Email
PRACTICAL cover image

Approval-style second factors are meant to be easy: you sign in, your phone buzzes, you tap “yes, that's me”, and you are through. The convenience is real, and so is the weakness attackers have learned to exploit. If someone already has your password, the only thing standing between them and your account is that tap - so they trigger the prompt and wait for you to press yes.

The attack has a name, “MFA fatigue”, and it is deliberately annoying. The attacker fires off approval requests, sometimes one after another late at night, betting that you will tap to make the buzzing stop, or assume the app is misbehaving, or genuinely think you must have started a sign-in and forgotten. Each unexpected prompt is not noise. It is the sound of your correct password being tried by someone who is not you.

The rule is simple and worth saying out loud: if a prompt appears that you did not just trigger, deny it. Do not tap yes to clear it, do not tap yes because it is the tenth one and you are tired. Denying it keeps the attacker out for that attempt; tapping yes hands them the account outright. When in doubt, deny, because a denied genuine sign-in costs you a retry, while an approved fraudulent one costs you everything behind it.

Then act on what the prompt told you, because it revealed something important: your password is known. Change it now, on that account and anywhere you reused it, and if the option exists, switch to number-matching or a passkey. Number-matching makes you type a code shown on the sign-in screen rather than tapping a blind yes, which quietly kills the fatigue attack because there is nothing to guess.

For teams, this is worth a two-minute briefing rather than a policy nobody reads. Tell people plainly that an unexpected approval prompt is a signal, not a bug, and that denying it and flagging it is exactly the right move - never something to feel foolish about. The staff member who denies a prompt at eleven at night and mentions it in the morning has just caught a live intrusion for you.

WHAT TO DO
  • ✓Treat any sign-in prompt you did not start as a warning, and deny it.
  • ✓Never approve a prompt just to stop it buzzing, however many arrive.
  • ✓After an unexpected prompt, change that password and anywhere it was reused.
  • ✓Switch on number-matching or a passkey so there is no blind ‘yes’ to exploit.