Because the prompt itself becomes familiar, and familiarity lowers scrutiny. When users expect constant verification, a fake login page or approval request can look like part of the normal process. The risk rises when the attacker can imitate the timing and appearance of routine access checks.
Why routine prompts change how people judge a login page
Repeated authentication prompts train users to treat verification as normal background noise. Once that expectation sets in, they stop using the prompt itself as a warning signal and start reacting to it automatically. That makes a fake login screen or approval request easier to accept because it looks like part of an ordinary access flow rather than an exception worth questioning.
Attackers benefit when a prompt feels familiar enough to bypass the user’s attention. The more often people see the same wording, branding, timing, and step-up challenge, the less likely they are to pause and check whether the request came from the real system.
How attackers turn prompt fatigue into phishing success
Phishing gets stronger when the attacker can mimic the rhythm of real authentication, not just the visual style. A fake prompt that appears during a normal workday, after a password change, or when a user expects an SSO refresh is more believable than an obviously odd request. That is why repeated prompts can be dangerous even when the underlying login control is legitimate.
The weak point is expectation management. If users are trained to see frequent verification as routine, they are less likely to notice small inconsistencies in domain names, device context, push wording, or the scope of what the prompt is asking them to approve. Familiarity lowers the threshold for click-through and approval.
Well-documented phishing patterns such as Twilio 0ktapus breach 2022 and MFA Guide show how attackers exploit that habit by copying familiar sign-in flows, OTP requests, and approval prompts. The same logic appears in CitrixBleed exploitation 2023, where stolen session material helped attackers get around normal verification entirely once trust had already been established.
Why reducing repeated prompts matters more than adding more of them
Security teams often add more prompts to force certainty, but that can have the opposite effect if it conditions users to approve by reflex. The better pattern is to prompt only when the risk truly changes, then make the prompt clearly tied to the user’s action and the current session state. Phishing-resistant methods reduce the chance that a user is asked to distinguish the real system from a convincing fake in the first place, which is why NIST SP 800-63 Digital Identity Guidelines and Passwordless and Passkeys Guide are relevant to this problem.
Teams should also notice when prompts are compensating for weak session design, not protecting a real step-up decision. If users see the same approval request over and over, the system may be teaching them to ignore the very signal defenders want them to trust. That is a security design failure, not a user-training problem alone.
Risk and Threat Considerations
Repeated prompts create exposure because they normalize the look and feel of authentication. Once that pattern is established, a phony request can ride on the user’s expectation that verification is supposed to happen now, making social engineering materially easier.
Failure mechanism: The attacker imitates a routine login or approval flow, and the user responds automatically because the prompt no longer feels exceptional or suspicious.
Impact: Users may disclose credentials, approve malicious MFA requests, or accept a fake sign-in page, which can lead to account takeover and downstream access to email, SaaS, or internal tools.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Covers phishing-resistant authentication and assurance decisions for repeated sign-in prompts. |
| Recommendation — Use phishing-resistant authenticators and reduce low-assurance prompts that users can learn to ignore. | ||
| OWASP ASVS | V6 — Authentication | Authentication prompts and MFA UX directly affect how users distinguish legitimate from fake login flows. |
| Recommendation — Verify authentication flows resist prompt replay, phishing, and approval fatigue. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Repeated prompts can normalize weak authentication experiences that attackers mimic or abuse. |
| Recommendation — Harden authentication so routine prompts cannot be impersonated with convincing fake requests. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access control practices should minimize unnecessary re-authentication that weakens user vigilance. |
| Recommendation — Review access workflows to remove avoidable prompts and tighten step-up decisions. | ||
Practitioner Guidance
What to prioritise: Reduce unnecessary re-prompts before you try to educate users about them. If the same user is seeing repeated challenges without a clear change in context, the control is likely creating fatigue instead of adding assurance.
What to verify: Check whether prompts are bound to a real risk event, such as a new device, impossible travel, privilege change, or fresh session. If not, the prompt is mainly training users to click through.
Common mistake: Treating more prompts as stronger security. In practice, excessive prompting can turn the authentication step into background noise and make phishing pages easier to trust.
Practitioner takeaway: The goal is not to ask for verification more often, but to make every verification event rare enough, specific enough, and trustworthy enough that users still notice when something is wrong.