MFA fatigue
Also known as Push bombing, MFA bombing
Spamming a user with approval prompts until they approve one just to make it stop.
The attacker already has the password and triggers sign-in after sign-in, often late at night. Eventually the target taps approve out of confusion or irritation, and the attacker is in.
Number matching largely defeats it by requiring the user to type a digit shown on the sign-in screen, which they cannot know unless they initiated it. Enabling that is a small configuration change with a large effect.
Where this comes up
MFA fatigue sits inside our identity and access work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.