Back to Blog

What to Do About an Unexpected MFA Prompt on a Shared Household Account

Deny an unclaimed MFA prompt, secure the shared account through a known path, and give every future approval one clear owner.

What to Do About an Unexpected MFA Prompt on a Shared Household Account

Deny an unexpected multifactor authentication prompt. Do not approve it to make the notifications stop. Tell the household, open the service through its official app or a saved bookmark, change the password, and review recent sign-ins and recovery details. Treat repeated prompts as evidence that someone may know the password, not as a harmless app glitch.

Stop the prompt without helping the attacker

An approval request should match an action someone in the household just started. Ask in your usual household channel, “Is anyone signing in to the electricity account?” Do not include a screenshot if it exposes an email address, device name, location, or one-time code.

If nobody claims the login, tap Deny or No, it’s not me. Never approve a prompt because a caller, text sender, or supposed support agent asks you to. A real support worker does not need you to authorize an unknown login.

Repeated requests are sometimes called MFA push bombing or MFA fatigue. The attacker hopes annoyance will produce one accidental approval. CISA identifies push bombing as a weakness of some MFA methods. Silence notifications temporarily if needed, but do not disable MFA.

Secure the account from a known path

One person should lead the response while another checks whether a legitimate household task caused the prompt. Use the provider’s app that is already installed, a saved bookmark, or a web address typed manually. Do not use a link supplied in the prompt, email, or follow-up text.

Then work through this order:

1. Change the account password to a unique password that is not used elsewhere.

2. Sign out other sessions if the provider offers that control.

3. Review recent sign-ins, devices, delegated users, and connected apps.

4. Check that recovery email addresses and phone numbers still belong to the household.

5. Remove any unfamiliar authentication method, passkey, forwarding rule, or app connection.

6. Save new recovery codes somewhere restricted and record who holds them.

If the same password was reused on another service, change it there too. If an unknown login completed a payment, changed service, or exposed personal data, contact the provider through its published support channel and preserve confirmation numbers.

Make approval ownership unambiguous

Shared credentials create a predictable problem: everyone can receive a prompt, but nobody knows who initiated it. Prefer named member access when the service supports it. Each resident then has a separate login and authentication method, and access can be removed without changing everyone’s credentials.

If one shared login is unavoidable, assign a primary approver and a backup. Before signing in, the person initiating it posts a short notice such as, “Gas account login now, approve one prompt from the iPad.” The approver checks that the timing and displayed details match. No advance notice means no approval.

Keep recovery planning separate from daily approval. The household can use the approach in two-factor authentication for shared household accounts to choose methods and backups without circulating a master password.

How HomeCo helps

HomeCo can hold the household procedure as a recurring reference task, not the secret itself. Create a checklist with the official support URL, the account owner, the backup responder, and the steps for reviewing sessions. Do not store passwords, one-time codes, recovery codes, or screenshots of security screens in a general household task.

When a suspicious prompt arrives, assign one incident task and use comments for non-sensitive updates: who denied it, when the password was changed, and whether provider support was contacted. Close the task only after recovery details and active sessions have been checked. That gives the household a useful handoff without turning a coordination app into a credential vault.

FAQ

What if someone approves the MFA prompt by mistake?

Change the password immediately from the official app or site, sign out other sessions, and inspect security settings for unfamiliar devices or methods. Contact the provider if you cannot regain control or if money or sensitive data may be affected.

Should we disable push notifications after repeated requests?

No. Deny the requests and secure the account. You can mute phone notifications briefly while responding, but removing MFA would also remove a protection the attacker is trying to defeat.

Can we ask everyone to send a screenshot of the prompt?

Avoid it unless provider support specifically needs one. Prompts can reveal account names, approximate locations, device details, or codes. A plain-text confirmation of who initiated the login is usually enough.