Phishing guide

What is MFA fatigue, and what should I do with an unexpected authentication prompt?

Respond safely to unexpected MFA push notifications, authentication codes, and repeated approval requests.

Content reviewed
Short answer

Deny an authentication prompt you did not initiate. Do not share a code or approve a request to make it stop. Open the account’s security activity independently and report repeated prompts through a known support channel.

What you may be seeing

An unexpected prompt can mean someone entered your username and password, a saved session is reconnecting, an application is misconfigured, or another benign or malicious event occurred.

Repeated prompts can pressure a person into approving one. CISA’s multi-agency guidance recommends controls such as number matching to reduce this pattern.

Signals to inspect—and why they matter

Strong evidence

You did not start a sign-in or account-change action

There is no reason to approve an authentication request you did not initiate. Denial is the safe immediate decision even before the cause is known.

A caller or message asks you to read back a code or approve a prompt

The code or approval is the authentication factor. Sharing or approving it can complete someone else’s sign-in.

Contextual signals

The displayed location looks unfamiliar

Location can be imprecise. The uninitiated prompt is the stronger signal; use account activity and support logs for investigation.

Contextual signals can justify caution, but they do not authenticate or condemn a message by themselves.

Safe verification steps

  1. Select Deny when the authenticator offers it; otherwise let the prompt expire.
  2. Open the service from a known app or bookmark and review recent security activity.
  3. For a work or school account, contact IT/security through the directory or normal help channel.
  4. If activity suggests the password is known, change it through the official service and replace any reused password.

What to do next

  • Report repeated prompts and the approximate time so an administrator can review sign-in logs.
  • Review registered authentication methods and remove ones you do not recognize through the official account portal.
  • Never approve a prompt merely because someone claiming to be support asks you to.
Evidence

Authoritative references

Reporting instructions on linked pages belong to the named organization. Baitaphish does not receive or process reports.

Limitations and uncertainty

What this guide cannot establish

  • An unexpected prompt does not, by itself, prove that a password was stolen or that a sign-in succeeded.
  • Prompt wording and controls differ across authenticator products and organization policies.