MFA fatigue attacks presuppose a prior compromise: the attacker already holds the username and password — from phishing, a breach dump, or infostealer malware — and the only barrier left is a push-based second factor. Because a simple “Approve / Deny” push requires no code and no context, the attacker repeatedly initiates logins so the victim’s phone buzzes again and again.
The wager is behavioral, not technical: that the victim will eventually approve to make the noise stop, assume it is a glitch, tap reflexively out of habituation, or be socially engineered into approving by a simultaneous call (“Hi, this is IT — we’re pushing an update, please approve the prompt”). The technique exploits the weakest common MFA design — simple approval push — and does not work against methods that require information the attacker lacks: number matching, or phishing-resistant FIDO2/passkeys bound to the specific site and device.
The lesson is two-part: recognize the flood as an attack signal — an unrequested approval prompt means someone already has your password — and migrate away from the approval-only factor that makes the flood viable.