Microsoft Authenticator - Constant Login Approval Requests


Recommended Posts

So for the last few days, and excuse me if I'm not posting in the correct place... anyway, for the last few days I have been getting constant login approval requests from Microsoft Authenticator. I thought maybe someone was trying to get in so I changed my password and backup info... it did stop for a bit after, but now, it's back. I've had maybe 10 today alone. I check the history and there is nothing there.... under my recent activity it just lists my login to view the page, and my last login attempt which I signed into Outlook on my phone on June 18. What is going on? It's asking me to 'type in the code' that's displayed on my screen. I'm not doing it! Anyone else? Anything I should dig deeper into?

Hello,

What sort of Microsoft Authenticator account login approval requests are you getting?  It is a generic authentication app and can be used with all sorts of services (Microsoft Account, Google Account, websites and services that support multi-factor authentication, etc.).

Regards,

Aryeh Goretsky

On 25/06/2026 at 03:27, goretsky said:

Hello,

What sort of Microsoft Authenticator account login approval requests are you getting?  It is a generic authentication app and can be used with all sorts of services (Microsoft Account, Google Account, websites and services that support multi-factor authentication, etc.).

Regards,

Aryeh Goretsky

It's requesting a login code as if I was signing into my account on my Windows machine. 

If you look at the account logs more than likely it will be showing that the request is coming from Valley Nebraska. we have been seeing thousands of these the last day or so.

On 25/06/2026 at 00:04, jbarcus81 said:

So for the last few days, and excuse me if I'm not posting in the correct place... anyway, for the last few days I have been getting constant login approval requests from Microsoft Authenticator. I thought maybe someone was trying to get in so I changed my password and backup info... it did stop for a bit after, but now, it's back. I've had maybe 10 today alone. I check the history and there is nothing there.... under my recent activity it just lists my login to view the page, and my last login attempt which I signed into Outlook on my phone on June 18. What is going on? It's asking me to 'type in the code' that's displayed on my screen. I'm not doing it! Anyone else? Anything I should dig deeper into?

Do not enter the code under any circumstances, or you will be sorry. It's definitely and most likely a hacking attempt.  That happened to me a couple of years ago, and I kept receiving those prompts for months.

It's simply the attacker trying to get you tired of the constant requests, so you just give up and enter the code, so they can log in to your account. 

Sounds like someone knows your email address and is repeatedly trying to log in, hoping you'll approve the MFA request (MFA fatigue). Definitely don't approve any prompts you didn't initiate. I'd also check that no unknown devices are signed into your account, sign out of all sessions, and consider changing your email.

On 25/06/2026 at 17:02, The_Focal_Point said:

Sounds like someone knows your email address and is repeatedly trying to log in, hoping you'll approve the MFA request (MFA fatigue). Definitely don't approve any prompts you didn't initiate. I'd also check that no unknown devices are signed into your account, sign out of all sessions, and consider changing your email.

Yeah, I signed out of everything when I changed the password to my account. I keep checking device history and there's never anything new other than my own activity. 

On 25/06/2026 at 10:40, _neutrino said:

If you look at the account logs more than likely it will be showing that the request is coming from Valley Nebraska. we have been seeing thousands of these the last day or so.

I checked on the IPs associated with every login and they're all mine... And whenever I get a new prompt, there is no activity to show for it. 

Hello,

Were you using a product or service from one of the companies affected by the Klue data breach?  See https://klue.com/blog/an-update-on-recent-klue-security-incident for the company's public statement.  That blog post does not list affected customer.

From looking around at reports, I created this list:

  • Gong
  • HackerOne
  • Huntress
  • Insurity
  • Jamf
  • LastPass
  • OneTrust
  • Recorded Future
  • ReliaQuest
  • Salesforce
  • Snyk
  • Sprout Social
  • Tanium

It is likely there are other companies affected as well.

Regards,

Aryeh Goretsky
 

@goretsky I will keep those in mind for the calls we get and update our technicians with the list, im sure the list will grow and I hope there is a larger public statement on this. 

Here is the statement from Huntress
https://www.huntress.com/blog/klue-breach-investigation

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Bunch of w*nkers. . 
    • Autonomous post-training loop placed 8th of 4,000 and then rewrote its own evaluation strategy. An autonomous AI system built by researchers at Amazon's A-EVO-Lab completed a full post-training run on a 30 billion parameter NVIDIA Nemotron model — with no human in the loop, across four rounds running over multiple weeks — and then did something its designers had not planned for: it detected that its own internal evaluation metric had become misleading and redesigned the search strategy it was using to improve itself. https://www.techtimes.com/articles/319123/20260626/nvidia-ai-trained-itself-30b-model-corrected-its-own-broken-metric-mid-run.htm
    • Grok Adult Content Tops 10 Billion Images Monthly More than half of all traffic flowing through Grok, Elon Musk's flagship AI product, now comes from users requesting pornographic images, explicit videos, and **** roleplay https://www.techtimes.com/articles/319142/20260626/grok-adult-content-tops-10-billion-images-monthly-xai-engineers-admit-csam-has-no-fix.htm
    • If Ford would stop hiring SUITS to run the company, and put CAR GUYS back in charge perhaps they could do better. Heck, the only CAR they produce today is the Mustang. Hey Ford! Not everyone needs/wants an overpriced SUV or pickup truck that is so tall you have to have a step ladder to get in and out of it.
    • Amazing how some will just jump all over something. Probably the same people that thought Musk was a "tech god" before he saddled up with "bad orange man". Before, they worshiped at his feet, including a lot of so called hollywood types. Now, because he fell off the plantation truck, they toss him under the bus.
  • Recent Achievements

    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
    • Week One Done
      tuben earned a badge
      Week One Done
    • First Post
      OffsetAbs earned a badge
      First Post
    • Reacting Well
      OffsetAbs earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      501
    2. 2
      +Edouard
      229
    3. 3
      PsYcHoKiLLa
      163
    4. 4
      Steven P.
      76
    5. 5
      FloatingFatMan
      71
  • Tell a friend

    Love Neowin? Tell a friend!