MFA bombing, sometimes called MFA fatigue, is a simple, effective attack built entirely on annoyance. An attacker who already has a stolen password triggers repeated login approval requests, hoping the target eventually taps "approve" just to make the notifications stop, especially late at night or mid-task.
It works precisely because MFA is normally a routine, low-attention action. A flood of unexpected prompts turns that routine into a nuisance people want to resolve quickly, which is exactly the moment an attacker is counting on.
The rule that defeats it is simple: an MFA prompt you didn't trigger yourself is never something to approve, no matter how many times it repeats. It should be reported, and the underlying password changed: a flood of requests is itself the warning sign, not a technical fault to dismiss.
See how goDeep turns thinking like this into training your team will actually remember.