Attackers can compromise accounts protected by multi-factor authentication by bombarding users with repeated MFA prompts until they accidentally or frustratedly approve a malicious login attempt. You should train employees to never approve unexpected MFA
Read the full article: https://thehackernews.com/2026/05/mfa-prompt-bombing-why-your-second.html