Many contractors have rolled out multi-factor authentication, and that is a real improvement. But attackers adapt. One common technique is to take a stolen password and try to log in repeatedly, triggering a stream of approval prompts on the victim's phone. Eventually, tired, distracted, or just wanting the buzzing to stop, someone taps approve. This is often called MFA fatigue or prompt bombing.
For field crews who are busy, wearing gloves, and constantly receiving notifications, the risk is real. This article explains how the attack works and what practical changes make it much harder to succeed.
How the Attack Works
The attacker first needs a valid username and password, usually obtained from a phishing page, a reused password in an earlier breach, or a malware infection. They then attempt to sign in. The system sends an approval request to the legitimate user's phone. The attacker repeats the attempt over and over, sometimes late at night, and may even call or message the person pretending to be IT support and urging them to approve.
The weakness is not the technology itself. It is that a simple "approve or deny" prompt asks a human to decide without context.
Warning Signs for Staff
Employees should know that these are red flags:
- An approval request they did not initiate
- Multiple prompts in quick succession
- A call, text, or email from someone claiming to be IT who asks them to approve
- A prompt at an odd hour when they are not working
The rule is simple and should be repeated often: if you did not just try to sign in, deny it, and report it.
Technical Changes That Help
Use number matching or code entry
Instead of a plain approve button, many authenticator apps can require the user to enter a number shown on the sign-in screen. An attacker who is not looking at the real screen cannot supply it. Microsoft 365 and other major platforms support this; confirm that it is turned on for your tenant.
Show context in the prompt
Enable features that display the application name and approximate location of the sign-in request. A prompt from a city the user has never visited stands out.
Limit repeated attempts
Configure lockouts or throttling so a stream of failed or repeated prompts triggers a block rather than endless notifications. Alert your IT team when an account receives repeated denials.
Prefer phishing-resistant methods
Hardware security keys and passkeys are significantly harder to trick because they bind authentication to the legitimate site and do not rely on approving a prompt. They are especially suitable for administrators, finance staff, and executives. CISA guidance encourages phishing-resistant authentication for high-value accounts.
Reduce reliance on text messages
SMS codes are better than nothing, but they can be intercepted through SIM swapping or phishing. Move critical accounts to an authenticator app or a security key.
Use conditional access
Policies can require compliant devices, block sign-ins from unexpected countries, or require stronger authentication for risky logins. Even a few simple rules cut noise and exposure.
Make It Work for Field Crews
Security that field staff cannot use will be bypassed. Consider:
- Shared devices. Where crews share tablets, use individual sign-ins with quick, supported methods rather than shared accounts.
- Poor connectivity. Choose methods that work with limited signal, such as codes generated in an app.
- Gloves and weather. Hardware keys that tap or plug in may be easier than typing codes; test options with real crews.
- Language and clarity. Provide short, clear instructions in the languages your crews speak.
Build a Response Habit
Teach everyone a three-step response to unexpected prompts:
- Deny the request.
- Tell IT or a supervisor right away, even if it seems minor.
- Do not approve anything requested by phone, text, or chat, no matter who claims to be calling.
Make reporting easy and free of blame. If someone accidentally approves, they should feel safe saying so immediately, because speed matters. IT can then reset the password, revoke sessions, and review the account.
After a Suspected Approval
If a prompt was approved by mistake, treat it as a compromise until proven otherwise. Reset the password, sign out active sessions, check mailbox rules and forwarding, review recent sign-in history, and watch for fraudulent payment requests sent from that account.
Getting Started
Check your current setup this week: is number matching enabled, are repeated prompts alerting anyone, and do administrators use stronger methods? Ironfield Cyber can review your multi-factor configuration and help you tune it so it protects the business without frustrating the crews who rely on it.