{"id":9694,"date":"2026-09-30T10:00:00","date_gmt":"2026-09-30T10:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9694"},"modified":"2026-09-30T10:00:00","modified_gmt":"2026-09-30T10:00:00","slug":"the-mfa-you-have-isnt-the-mfa-you-think-you-have","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9694","title":{"rendered":"The MFA you have isn\u2019t the MFA you think you have"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they\u2019ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason \u2014 adding a second factor to a password login closed off an enormous share of credential-based attacks, and organizations that adopted it early saw the payoff in fewer compromised accounts.<\/p>\n<p class=\"wp-block-paragraph\">That confidence is now outdated in a way many security teams haven\u2019t fully registered. The MFA adoption rate reported to a board or an auditor rarely distinguishes between the method used to satisfy it. A push notification and a hardware security key both count as \u201cMFA enabled\u201d on the same compliance report, and so does a one-time code sent by SMS \u2014 despite sitting at wildly different points on the spectrum of what an attacker can defeat. Uber\u2019s 2022 breach, <a href=\"https:\/\/techcrunch.com\/2023\/09\/14\/mgm-cyberattack-outage-scattered-spider\/\">the MGM Resorts incident<\/a>, and a growing list of enterprise intrusions traced back to compromised help desks all shared the same root cause: MFA was present, and MFA still failed, because the method in place was never built to resist a targeted attacker.<\/p>\n<h2 class=\"wp-block-heading\">Where push and OTP fail<\/h2>\n<p class=\"wp-block-paragraph\">Push notification MFA came first for most organizations, mainly because it was the path of least resistance \u2014 nothing for the user to remember, nothing to type and IT could turn it on across the company in an afternoon. That same ease of rollout turned out to be exactly what made it easy to break. Attackers figured out they didn\u2019t need to steal anything sophisticated. They just needed a stolen password and the willingness to send the same approval prompt to someone\u2019s phone over and over, sometimes for hours, until the user got annoyed enough \u2014 or tired enough, or confused enough \u2014 to tap approve. Security teams call this <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf\">push fatigue or MFA bombing<\/a>. It works often enough that it\u2019s now one of the most common ways attackers get past MFA that\u2019s technically \u201con.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The OTP problem is simpler and uglier than push fatigue. It\u2019s just a code, and a code can be gotten. Sometimes an attacker convinces a mobile carrier to move a victim\u2019s phone number onto a SIM they control \u2014 a scam that\u2019s quietly drained crypto wallets and corporate email accounts for years now. Increasingly, though, it doesn\u2019t even require that much effort. Phishing kits built around reverse-proxy tools can now intercept an OTP in real time \u2014 the victim types their password and code into what looks like a normal login page, unaware that the page is quietly forwarding everything to the real site on the attacker\u2019s behalf, session and all.<\/p>\n<p class=\"wp-block-paragraph\">Both failure modes share a simple design gap. The authentication method never verifies that the person approving the login and the system requesting it are talking to the same, legitimate destination. That\u2019s the property attackers exploit, and it\u2019s exactly the property newer standards were built to close.<\/p>\n<div class=\"extendedBlock-wrapper block-coreImage undefined\"><button class=\"lightbox-trigger\">\n<p>\t\t\t<\/p><\/button>\n<p class=\"imageCredit\">Ashish Mishra<\/p>\n<\/div>\n<h2 class=\"wp-block-heading\">The property that closes the gap<\/h2>\n<p class=\"wp-block-paragraph\">Ask what stops a phishing site from working against <a href=\"https:\/\/fidoalliance.org\/passkeys\/\">FIDO2 or a passkey<\/a>, and the answer isn\u2019t cleverness \u2014 it\u2019s math. A passkey has no code to steal in the first place. What gets created during enrollment is a cryptographic key pair locked to one website, permanently, and a lookalike domain simply isn\u2019t that website, no matter how convincing it looks to a human eye. The browser checks the origin before anything else happens, finds it doesn\u2019t match and the login attempt dies right there \u2014 before the user can ever be fooled into approving something they shouldn\u2019t.<\/p>\n<p class=\"wp-block-paragraph\">This origin-binding is the entire point, and it\u2019s worth being precise about it, because vendors market a wide range of products under the \u201cphishing-resistant\u201d label without all of them meeting the bar. A hardware key that still allows a fallback OTP option isn\u2019t resistant if that fallback stays reachable. A passkey stored insecurely on a shared or unmanaged device narrows the gap but doesn\u2019t close it entirely. The strength of the control depends on the full authentication path, not just the strongest link in it.<\/p>\n<h2 class=\"wp-block-heading\">The migration nobody wants to admit is hard.<\/h2>\n<p class=\"wp-block-paragraph\">If the technical argument for phishing-resistant MFA is this strong, the natural question is why so many organizations still run on push and OTP. The honest answer isn\u2019t ignorance. It\u2019s friction, and pretending otherwise doesn\u2019t help anyone plan a migration.<\/p>\n<p class=\"wp-block-paragraph\">Older on-premises systems weren\u2019t built with WebAuthn in mind, and neither were some SaaS platforms still in wide use \u2014 so somebody ends up bolting on a compensating control or finding a workaround, because ripping and replacing isn\u2019t realistic on most timelines. Hardware keys aren\u2019t free either \u2014 multiply even a modest per-user cost across a large workforce, and it adds up fast, and unlike a push notification, a lost or damaged key turns into an actual support ticket. Then there\u2019s the part nobody likes admitting out loud: employees who are used to tapping approve on their phone in two seconds are going to notice, and complain, when the new process means digging a physical key out of a bag and plugging it in. None of that means the migration isn\u2019t worth doing. It means it needs a rollout plan behind it instead of a memo telling everyone to switch by Friday.<\/p>\n<h2 class=\"wp-block-heading\">Starting small, on purpose<\/h2>\n<p class=\"wp-block-paragraph\">The organizations making real progress on this aren\u2019t converting their entire workforce overnight. They\u2019re starting where the risk is concentrated, and the resistance to change is lowest: administrator accounts, identity provider access and anyone with the ability to reset another user\u2019s credentials. These are the accounts attackers target first precisely because compromising one unlocks everything downstream, and they\u2019re also the accounts where a small population of technically capable users can absorb a new workflow without much disruption.<\/p>\n<p class=\"wp-block-paragraph\">Finance and engineering come next, along with any other group sitting close to sensitive systems. Legacy applications that can\u2019t yet support the new standard don\u2019t get a permanent pass \u2014 they get a conditional access policy in the meantime and a real deadline for when the exception closes. SMS-based OTP should get the same treatment, except with less patience. Of every method still in common use, its weaknesses are the best documented and the most actively exploited, which is exactly why it should carry a sunset date instead of sitting around indefinitely as a fallback.<\/p>\n<p class=\"wp-block-paragraph\">Attackers have already retooled around the MFA most organizations deployed years ago. Waiting for a bigger incident to justify the migration isn\u2019t a strategy; it\u2019s a bet that your organization won\u2019t be next. Start with an honest audit: not which accounts have MFA enabled, but which method is protecting each one.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>For nearly a decade, multi-factor authentication has been the control every security leader points to when asked how they\u2019ve reduced account takeover risk. It sits on almost every compliance checklist and nearly every cyber insurance questionnaire, and for good reason \u2014 adding a second factor to a password login closed off an enormous share of [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9615,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9694"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9694"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9615"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}