An unexpected sign-in approval appears on your phone. Then another one arrives, followed by several more. You did not try to sign in, but the requests keep coming.
This is push bombing. A criminal often already has your password and repeatedly tries to sign in, hoping you will approve one request to make the notifications stop. One tap can give them access to your email, files and other business systems.
Why sign-in approval is still important
Multi-factor authentication adds a second check after a password. That second check stops many account takeovers because a stolen password is not enough on its own.
Push bombing does not make multi-factor authentication useless. It targets the person receiving the request. The criminal relies on confusion, interruption or frustration.
Any sign-in request you did not start is a warning that someone may know your password.
How push bombing works
The attacker first obtains a username and password, often through a scam email, a reused password exposed elsewhere or a fake sign-in page.
They then try to sign in repeatedly. Each attempt sends an approval request to the account owner's phone or authentication app. The attacker hopes the person will approve a request by mistake or assume it relates to something they were already doing.
A legitimate approval request should only appear when you have just entered your password for that account. If the timing does not make sense, reject it.
What staff should do
If you receive an approval request you did not start:
- Do not approve it.
- Reject or report the request if the app gives you that option.
- Contact your IT support provider or the person responsible for security.
- Change the account password from a trusted device.
- Check the account for unfamiliar sign-ins or changes.
Do not keep dismissing requests without reporting them. Repeated prompts can mean the password has already been stolen.
Make approvals harder to trick
Some sign-in systems show a number on the login screen and ask the user to enter it in the authentication app. This is safer than a simple Approve button because the user must be looking at the sign-in screen.
Security keys and passkeys can provide stronger protection. They check that the user is signing in to the genuine service and do not rely on a push approval. The right option depends on the accounts, devices and work practices in your business.
Reduce the chance of password theft
Every business account should have a unique password. A password manager makes this practical by creating and storing strong passwords without asking staff to remember them all.
Remove accounts that are no longer needed, review old apps and restrict access to the people who need it. Fewer unmanaged accounts mean fewer places for passwords to be lost or reused.
Put a clear reporting process in place
Staff need to know who to contact and what to say when an unexpected approval appears. Reporting should be quick and blame free. Fast action gives your IT provider a chance to reset the password, end active sessions and check whether the account was accessed.
Include this situation in staff security training. A short, practical example is more useful than a long technical lesson.
If unexpected approvals are arriving now, reject them and call your known IT support number. Do not wait for the prompts to stop.
To prevent the next attempt, contact JCPIT for a sign-in security review. We will check approval methods, recovery access and the staff reporting path.