Skip to Content

4. When 2FA Asks and You Did Not Log In

LESSON 4 OF 6 · 5 MIN

When 2FA Asks and You Did Not Log In

This is the most important lesson in the course. Everything so far was setup. This is the moment that decides whether an attack succeeds.

One day your phone will show an approval request, or a code will arrive — and you were not signing in to anything.

What that means, precisely

Somebody already has your password and is trying to use it right now. The second lock is the only thing standing between them and your account.

What attackers count on

When the first prompt is denied, attackers often send another. And another. Late at night, over and over, until the phone will not stop buzzing. The goal is simple: make you tap "Approve" just to end the noise. It has a name — MFA fatigue — and it works often enough that it has become a standard technique.

Some attackers go further and call you first, claiming to be from IT or from your provider, saying that you will receive a code and should read it out or approve it. No legitimate IT department, bank or supplier will ever ask you for that code. We will not ask you either.

What to do — three steps, in this order

  1. Deny the request. Never approve a prompt you did not trigger, no matter how many times it repeats.
  2. Change your password immediately, from a device you trust.
  3. Tell us right away — even at two in the morning, even if you are not sure.

You will never be blamed for reporting this. An unexpected prompt is not an annoyance; it is your early warning that a password has already leaked. Reporting it within minutes is often the difference between a five-minute password reset and a three-week investigation.

Commenting is not enabled on this course.