Skip to main content

    MFA Manipulation and Account Takeover: What to Do

    Do not approve a sign-in or share a security code because someone asks you to. Unexpected MFA prompts can signal an attempt to take over your account.

    By ZoraSafe · Content reviewed

    What MFA manipulation means

    Multi-factor authentication adds a check beyond a password. Attackers may try to make you complete that check for them: repeated push prompts, a fake login page, a caller posing as helpdesk staff or an unexpected password-reset request.

    MFA fatigue, or push bombing, means repeated requests intended to wear you down. A recovery code is also a credential; keep it out of chats, calls and screenshots sent to strangers.

    Sources: CISA: Require multifactor authentication; CISA: Implementing phishing-resistant MFA; FTC: How to recognize and avoid phishing scams

    If you receive an unexpected prompt

    1. Deny it. Do not approve a prompt just to stop the notifications.
    2. Open the account’s official app or type its known address yourself. Review sign-in activity and security settings.
    3. Contact support or your workplace IT team using a known channel, not a number supplied by the caller.
    4. If you shared a code, approved a request or changed recovery details under pressure, begin account recovery promptly.

    Sources: CISA: Require multifactor authentication; FTC: How to recover your hacked email or social media account

    A stolen session can bypass a new login

    A session token keeps you signed in after authentication. If it is stolen, an attacker may reuse access without triggering a fresh password/MFA challenge. That is why changing a password alone is not always the full response.

    Use the provider’s security tools to review signed-in devices and revoke suspicious sessions. Check recovery methods, forwarding rules and connected applications too.

    Sources: CISA: Social media account protection; FTC: How to recover your hacked email or social media account

    Make the next attempt harder

    Use phishing-resistant MFA, such as supported passkeys or security keys, where the account offers it. CISA describes number matching as an improvement over simple push approval when phishing-resistant options are not yet available.

    No MFA choice replaces verifying an unexpected request or securing a compromised device. Follow the recovery instructions for the account affected.

    Sources: CISA: Implementing phishing-resistant MFA; CISA: Require multifactor authentication

    Sources and product references

    Reviewed 2026-10-07. Source dates and scope matter; a linked source supports the associated guidance, not every claim about every product.