Multi-factor authentication (MFA) significantly reduces the risk of password theft, but it doesn't stop modern identity attacks that target the authentication process itself. Techniques such as adversary-in-the-middle phishing, push fatigue, and session replay can bypass many common MFA methods without defeating the password itself.

Passwords remain reusable shared secrets, a weakness we've unpacked in why passwords are still your biggest identity risk, and MFA was designed to reduce the risks that come with them. The real question is whether MFA changed the underlying authentication model or simply added another hurdle for attackers to overcome.

MFA reduced password risk, but not modern identity attacks

Multi-factor authentication raised the bar significantly against the attacks passwords were originally vulnerable to: guessing, credential stuffing, and the reuse of passwords leaked in unrelated breaches. Requiring a second factor meant a stolen password alone was no longer enough to gain access, and for a long time that represented a genuine improvement in enterprise security.

Many successful attacks no longer stop at stealing a password. They target the authentication process itself, intercepting approval prompts, one-time codes, or authenticated sessions to bypass common MFA implementations. MFA assumes the second factor is being approved by the legitimate user in a legitimate context. Several widely used attack techniques exist specifically to break that assumption.

None of this means MFA has failed. SMS codes and authenticator apps still prevent a large proportion of automated attacks. The challenge is that organisations facing targeted identity attacks need to think beyond whether MFA is enabled and consider whether it is phishing-resistant.

Phishing-resistant authentication is not the same as MFA

These two terms are often used interchangeably, but they describe different things.

phishing resistant vs MFA

MFA describes a requirement: a user proves their identity using more than one factor. It says nothing about how resistant those factors are to interception or manipulation. A one-time code sent by SMS and a hardware security key are both forms of MFA, but they sit at opposite ends of how difficult they are to defeat.

Phishing-resistant authentication, including FIDO2 security keys and passkeys, is a design approach rather than a category of MFA. It relies on cryptographic proof that's bound to the legitimate device and website, leaving no code, approval prompt, or reusable credential that can be intercepted, relayed, or replayed. An organisation can have MFA deployed across its entire environment and still have very little of it that is genuinely phishing-resistant.

How do attackers bypass common MFA implementations?

 

common MFA implentations

Push fatigue

An attacker who already holds a valid username and password repeatedly sends approval prompts to the legitimate user's device, often late at night or during a busy period, until one is approved out of frustration or habit rather than deliberate consent.

This technique was behind the 2022 Uber breach, where a contractor approved a prompt after being flooded with requests over several hours. It has since featured in other major intrusions attributed to the Scattered Spider group, including the 2023 MGM Resorts and Caesars Entertainment breaches.

SMS interception

One-time codes delivered by SMS can be intercepted through SIM swapping, where an attacker convinces a mobile carrier to transfer a victim's phone number to a device they control, or through weaknesses in legacy telecommunications protocols.

Once intercepted, the code functions exactly as intended, for whoever possesses it.

Adversary-in-the-middle phishing

Adversary-in-the-middle (AiTM) phishing has become one of the most effective ways of bypassing traditional MFA.

A phishing kit operates as a reverse proxy between the victim and the legitimate login page, relaying authentication requests in real time. Hence, the fake page behaves exactly like the genuine one. The victim enters their password and approves their MFA prompt as normal.

The attacker doesn't need the password afterwards. They capture the authenticated session token issued immediately after login, allowing them to access the service without re-authenticating.

Commercial phishing kits such as Tycoon 2FA have industrialised this technique, making sophisticated AiTM attacks accessible to attackers with relatively little technical expertise.

Session replay

Once a session token has been captured, whether through an AiTM phishing kit, endpoint malware, or another compromise, it can often be reused directly.

Authentication has already taken place. From the application's perspective, the session is already trusted, leaving no reason to challenge the user again.

The board question that matters more than whether MFA is enabled

The most important question is whether your organisation's authentication can still be phished.

Most boards have moved beyond asking whether MFA has been deployed. Coverage alone says very little about resilience because the techniques above succeed precisely because a factor exists that can be approved, intercepted, or replayed by someone other than the legitimate user.

A more valuable question is: Can our authentication still be phished?

That shifts the conversation from deployment numbers to authentication strength. It focuses attention on which MFA methods are actually being used, whether they rely on reusable credentials, and whether those credentials can still be captured or replayed.

At The Missing Link, we've found the conversation with Australian organisations has increasingly shifted from "Do we have MFA?" to "Can our authentication still be phished?" That distinction has become far more meaningful for security leaders reporting to executive teams and boards.

For organisations relying on a combination of SMS codes, authenticator app prompts and push approvals, the honest answer is often yes.


Frequently asked questions

Is MFA still worth using?

Yes. MFA significantly reduces the risk of password guessing, credential stuffing, and other automated attacks. The challenge is that some common MFA methods remain vulnerable to targeted attacks such as adversary-in-the-middle phishing and session replay, which is why phishing-resistant authentication is becoming increasingly important.

What is number matching, and does it stop push fatigue attacks?

Number matching requires the user to enter a number displayed on their login screen into the approval prompt rather than simply tapping Approve. It reduces accidental approvals but doesn't eliminate targeted attacks where users are persuaded to enter or share the correct number.

Are hardware security keys different from authenticator apps?

Yes. Authenticator apps generate a time-based code or approval prompt that still relies on the user or the network to relay it correctly. Hardware security keys use public-key cryptography that's bound to the legitimate website or application, preventing phishing sites from completing the authentication process.

Is SMS-based MFA still better than no MFA?

Generally, yes. SMS-based MFA continues to stop many low-effort attacks such as basic credential stuffing. However, it provides less protection against targeted attackers because techniques such as SIM swapping and telecommunications interception remain well established.

 


Looking beyond traditional MFA

Understanding where common MFA methods fall short raises a more important question: what should replace them?

That's the question we turn to next: how passwordless authentication removes the reusable credential altogether, rather than adding another factor for attackers to work around.

Our whitepaper, Reimagining Access: The Business Value of Passwordless Authentication at Scale, explores how phishing-resistant, passwordless authentication changes the identity model, reduces reliance on reusable credentials, and helps organisations strengthen identity security at enterprise scale.

Download the whitepaper

Prefer to talk it through? Contact The Missing Link to discuss your identity security roadmap. 


Latest insights

 

Author

Ruchit Deshpande

Ruchit Deshpande is the Security Solutions Director at The Missing Link, where he leads a team of talented Security Architects to help organisations build stronger, smarter cyber defences. With a lifelong passion for cyber security and over a decade of industry experience, Ruchit specialises in solving complex security challenges with practical, human-centred solutions. When he's not tackling emerging threats, you’ll likely find him playing or watching cricket or deep in thought over the latest cyber trends.