Attackers now bypass basic MFA routinely, so having MFA is no longer enough.
The type of MFA matters.
The MFA Ladder, Weakest to Strongest
| Method | How it works | Weakness |
|---|---|---|
| SMS / voice OTP | Code sent to phone | SIM swapping, SS7 interception, phishable |
| Email OTP | Code sent to inbox | Only as secure as the email account |
| Authenticator app (TOTP) | Time-based code in an app | Can still be phished in real time |
| Push notification | Tap “Approve” | MFA fatigue / prompt bombing |
| Push with number matching | User types the number shown on screen | Much better, but not phishing-proof |
| FIDO2 / passkeys / hardware keys | Cryptographic check bound to the site’s domain | Phishing-resistant; hardware keys need to be issued |
Real Attack Techniques
- MFA fatigue: the attacker spams push prompts until the user taps approve. This was used in the 2022 Uber breach.
- Adversary-in-the-middle (AiTM) phishing: kits like Evilginx proxy the real login page and steal the session cookie after MFA completes.
- SIM swapping: the attacker convinces the carrier to move the victim's number to a SIM they control.
- Help desk social engineering: the attacker calls support pretending to be the user and gets MFA reset.
Why FIDO2 and Passkeys Resist Phishing
- The credential is tied to the real domain, so a fake site can't use it.
- No shared secret is ever typed in, so there's nothing to steal.
Recommendations
- Retire SMS for privileged users.
- Turn on number matching for push.
- Require FIDO2 for admins and executives.
- Tighten the help desk's identity checks before any MFA reset.
Takeaway
Aim for phishing-resistant MFA. CISA and NIST guidance both push organizations in this direction.
Moving to phishing-resistant MFA? Book a 15-min demo of AuthNull.