← Blog
Asif
AsifSeptember 29, 2026

Not All MFA Is Equal: SMS, OTP, Push, and Phishing-Resistant MFA


Attackers now bypass basic MFA routinely, so having MFA is no longer enough.

The type of MFA matters.

The MFA Ladder, Weakest to Strongest

MethodHow it worksWeakness
SMS / voice OTPCode sent to phoneSIM swapping, SS7 interception, phishable
Email OTPCode sent to inboxOnly as secure as the email account
Authenticator app (TOTP)Time-based code in an appCan still be phished in real time
Push notificationTap “Approve”MFA fatigue / prompt bombing
Push with number matchingUser types the number shown on screenMuch better, but not phishing-proof
FIDO2 / passkeys / hardware keysCryptographic check bound to the site’s domainPhishing-resistant; hardware keys need to be issued

Real Attack Techniques

  • MFA fatigue: the attacker spams push prompts until the user taps approve. This was used in the 2022 Uber breach.
  • Adversary-in-the-middle (AiTM) phishing: kits like Evilginx proxy the real login page and steal the session cookie after MFA completes.
  • SIM swapping: the attacker convinces the carrier to move the victim's number to a SIM they control.
  • Help desk social engineering: the attacker calls support pretending to be the user and gets MFA reset.

Why FIDO2 and Passkeys Resist Phishing

  • The credential is tied to the real domain, so a fake site can't use it.
  • No shared secret is ever typed in, so there's nothing to steal.

Recommendations

  • Retire SMS for privileged users.
  • Turn on number matching for push.
  • Require FIDO2 for admins and executives.
  • Tighten the help desk's identity checks before any MFA reset.

Takeaway

Aim for phishing-resistant MFA. CISA and NIST guidance both push organizations in this direction.

Moving to phishing-resistant MFA? Book a 15-min demo of AuthNull.


← Back to Blog