Prompt Bombing Turned Your Second Factor Into a Doorbell Nobody Stops Ringing

Attackers stopped trying to steal push notifications. They just wait for tired users to tap 'approve' at 2 a.m.

ThreatVectr Newsdesk· 2 min read
Prompt Bombing Turned Your Second Factor Into a Doorbell Nobody Stops Ringing
Share

Think of MFA push prompts like a hotel concierge calling your room every five minutes to confirm you ordered room service. By the eighth call, you'd say yes just to make it stop. That's prompt bombing, and it's how Lapsus$ walked into Uber in September 2022 after buying a contractor's credentials and spamming push approvals until the contractor caved.

The mechanics are dumber than the damage suggests. An attacker with valid stolen credentials (harvested via infostealers like Lumma or Redline, or bought wholesale on Russian Market for under $20) triggers the legitimate MFA flow over and over. Microsoft Authenticator, Duo, Okta Verify — they all dutifully forward the push to the user's phone. Tap once. Game over.

And the attackers have gotten patient.

Mandiant's tracking of UNC3944 (the cluster behind the MGM and Caesars intrusions in September 2023) showed the group combining prompt bombing with social engineering calls to help desks, where they'd pose as the locked-out employee mid-bombardment and ask IT to "just approve it for me." CISA flagged the same pattern in its Scattered Spider advisory, noting the group's heavy reliance on MFA fatigue against US hospitality and gaming targets.

The fix isn't more MFA. It's better MFA. Number matching, where the user has to type a code shown on the login screen into their authenticator app, kills prompt bombing dead because the attacker doesn't see the code. Microsoft made number matching the default for Authenticator in May 2023, and Okta shipped its equivalent ("Verify with Number Challenge") around the same time. Duo has had it for years under the name Verified Push.

Phishing-resistant factors go further. FIDO2 security keys and passkeys bind the authentication to the actual origin domain, so even a perfectly executed adversary-in-the-middle attack via Evilginx or Tycoon 2FA can't replay the session. CISA has been beating this drum since its phishing-resistant MFA guidance dropped in October 2022.

But adoption is the problem nobody wants to talk about. A 2024 Cisco Duo Trusted Access report put number-matching adoption at roughly 40% of push-based MFA deployments, which means more than half of enterprises running "modern" MFA are still vulnerable to a teenager with a phone and patience. Help desk procedures are worse — most still allow voice-only identity verification, which is exactly the gap Scattered Spider keeps walking through.

So the second factor isn't broken. The human attached to it is exhausted.

Watch which insurers start refusing to write cyber policies for organisations still running plain push approval next renewal cycle.

© 2026 Threat Vectr