Posted on

Security-alert fatigue exploited by repeated fraudulent notifications

Security warnings are supposed to interrupt routine behavior.

The problem begins when interruption becomes routine behavior.

Microsoft describes “push-bombing” or MFA-fatigue attacks in which an attacker repeatedly triggers authentication requests to a victim’s device. The victim is expected to deny the requests. The attacker is betting that enough buzzing, tapping, and confusion will eventually produce one accidental or exhausted approval.

See Microsoft’s security guidance on push-bombing and credential attacks.

Microsoft later reported observing roughly 6,000 MFA-fatigue attempts per day by the end of June 2023 and described repeated notifications as a social-engineering technique that can overwhelm or distract users.

See Microsoft’s guidance on protecting credentials from social engineering.

The attacker turns a safeguard into noise

An unexpected authentication prompt is useful because it tells the user that someone is attempting to sign in.

Twenty unexpected prompts create a different psychological problem.

The user may start treating them as background noise, assume the system is malfunctioning, or approve one simply to make the interruption disappear. That is alert fatigue: the warning remains technically visible while its ability to command careful attention declines.

This is not limited to authenticator apps. Fraudulent security emails, password-reset notices, browser warnings, and fake account alerts can all benefit from the same exhaustion if users are conditioned to click through warning after warning.

Do not resolve an unexpected alert through the alert itself

If you receive an authentication request you did not initiate, deny it.

Then open the account or security dashboard through a known route and inspect recent sign-in activity. Change a compromised password if appropriate, review active sessions, and use stronger authentication options the provider supports.

Microsoft has pushed number matching and phishing-resistant authentication partly because a simple Approve button is easier to abuse through repeated prompting.

See Microsoft’s phishing-resistant MFA guidance.

The important habit is to separate notification from action.

A warning can tell you something may be wrong.

It should not automatically decide what you click next.

The scammer wants the hundredth alert to receive less thought than the first.

Security only works if the hundredth one still gets checked.