Stolen or weak credentials are consistently among the top causes of breaches in reports like the Verizon Data Breach Investigations Report (DBIR).
A password is a single secret. Once it leaks, nothing else protects the account.
What MFA Actually Is
MFA combines two or more of these factor types:
- Something you know: a password or PIN.
- Something you have: a phone, hardware key or smart card.
- Something you are: a fingerprint or face.
Two passwords is still one factor. The factors have to come from different categories.
How Passwords Get Compromised
- Phishing and fake login pages.
- Credential stuffing, which reuses passwords leaked from other sites.
- Brute force and password spraying.
- Keyloggers and infostealer malware.
How MFA Breaks the Attack Chain
A stolen password alone is no longer enough to log in.
Microsoft has reported that MFA blocks more than 99% of automated account-compromise attacks.
Common Objections, With Answers
- “It slows users down.” Push approvals and biometrics take seconds.
- “We're too small to be a target.” Automated attacks don't pick targets by size.
- “It's expensive.” A breach costs far more than the rollout.
Takeaway
Turn on MFA for email, VPN, cloud consoles and admin accounts first.
Ready to roll out MFA? Book a 15-min demo of AuthNull MFA.