How it works
The attacker obtains the password through phishing, an infostealer or credential stuffing, then tries to sign in again and again, generating a stream of approval requests on the victim's phone, often at night. Many attackers combine this with a message or call pretending to be IT support and asking the user to accept the prompt.
A known case
In the 2022 breach at Uber, an attacker with a contractor's password sent repeated MFA requests and then contacted the contractor on WhatsApp, posing as IT support. The contractor accepted a request, which gave the attacker access to internal systems.
Prevention
Use number matching, where the user must type a number shown on the login screen, and show the location and application in the prompt. Limit the number of push requests and alert on bursts of them. For administrators and high risk roles, move to phishing resistant methods such as passkeys or security keys. Conditional access can block sign ins from unknown devices before a prompt is even sent.
What users should know
Never approve a request you did not start, and report unexpected prompts immediately, because they mean someone already has your password. IT will never ask you to accept an MFA prompt by phone or chat. These messages belong in security awareness training, and an unexpected prompt should trigger a password reset.




