Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesYes. Attackers can relay a login and the second-factor step through a fake site, steal the authenticated session, pressure users into approving a push request, or intercept phone-based codes. Two-factor authentication still blocks many account takeovers, but the method matters: origin-bound passkeys and FIDO2 security keys are designed to stop phishing proxies.
How phishing gets around ordinary 2FA
Adversary-in-the-middle steals the session after you authenticate
An adversary-in-the-middle (AiTM) campaign places a convincing login page between you and the real identity provider. You enter your password on the look-alike page, which relays it to the genuine service. When the service asks for an authenticator code or approval, the proxy relays that step as well.
After the real service accepts the login, it returns an authenticated session token or cookie. The attacker captures that token and reuses it from another browser. The result is a valid session even though you completed MFA correctly. The stolen session can outlive the original password prompt until it expires or is revoked.
Push bombardment exploits a human decision
In an MFA-fatigue or push-bombing attack, criminals repeatedly send approval prompts. The user may accept one to stop the interruptions, mistake it for a legitimate sign-in, or approve while distracted. Number matching can reduce accidental approvals by requiring a code shown on the sign-in screen, but it does not bind the approval to the genuine website and is not equivalent to phishing-resistant FIDO/WebAuthn authentication.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Phone-number infrastructure can be attacked
SMS and voice codes can be redirected through SIM swaps, in which a carrier account is moved to an attacker-controlled SIM. Older signaling weaknesses, including SS7 exploitation, can also enable interception or redirection. Email one-time passwords face mailbox compromise and forwarding-rule abuse. Microsoft and CISA warn that SMS, email OTP and ordinary push methods remain exposed to interception, spoofing, phishing or social engineering.
A passed prompt does not prove the browser is safe
MFA proves that the identity provider accepted a factor at a particular moment. It does not prove that the page displaying the prompt was genuine or that the resulting browser session stayed with you. Treat an unexpected MFA request, a new-device alert or a sign-in you did not initiate as a possible compromise, not as evidence that your account is protected.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What the recent figures actually show
The available measurements indicate substantial pressure on identity systems, but they are organization-specific or drawn from particular incident samples rather than a universal bypass rate.
- Microsoft reported 7,000 password attacks per second in a 2024 article, a 75% year-over-year increase for the period it cited.
- Microsoft said more than 40% of users were employing MFA in that same 2024 reporting context.
- In 2025, Microsoft reported that 92% of its employee productivity accounts were protected by phishing-resistant authentication.
- The Canadian Centre for Cyber Security identified more than 100 campaigns targeting Microsoft Entra ID accounts between 2023 and early 2025. In that campaign dataset, 12.5% of cases involved full-session compromise in the third quarter of 2024.
- Microsoft reported in 2025 that nearly one quarter of its incident-response cases with an identified initial-access vector incorporated phishing or social engineering.
Those numbers describe the organizations, periods and samples named above. They should not be read as a population-wide probability that any particular MFA prompt will be bypassed.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Which second factors resist phishing?
The practical difference is whether the factor is merely a secret or approval that can be relayed, or a cryptographic assertion tied to the real website’s origin.
| Method | Phishing resistance | Interception risk | Social-engineering exposure | Recovery complexity | Platform support | Deployment cost | User friction |
|---|---|---|---|---|---|---|---|
| SMS or voice OTP | Low; codes can be entered into a proxy | High relative risk from SIM swaps, SS7 and message theft | High; attackers can impersonate support or a carrier | Usually low until a number is lost or hijacked | Broad cellular reach | Usually low per user; carrier charges may apply | Low |
| Email OTP | Low; the code can be relayed | Depends on mailbox security and forwarding controls | High if the mailbox or help desk is socially engineered | Moderate; recovery depends on another trusted channel | Broad where email is available | Usually low | Low to moderate |
| Authenticator push | Low against AiTM; vulnerable to approval fatigue | Push traffic itself is harder to intercept than SMS, but the approval can be phished | High without number matching and user training | Moderate; device replacement and re-enrollment are required | Requires a supported authenticator app | Usually low | Low until repeated prompts become disruptive |
| Number matching | Better than an unnumbered push, but not origin-bound | Still vulnerable to a relay that displays the attacker’s number | Reduced push-bombing risk, not eliminated social engineering | Moderate | Provider and app support required | Usually low | Moderate because the user enters a number |
| Passkey (FIDO2/WebAuthn) | High; the browser signs only for the registered origin | Private key is not sent to the website or an SMS channel | Lower for remote phishing, though enrollment and recovery can still be attacked | Moderate; users need a synchronized passkey or another registered authenticator | Modern browsers, operating systems and services; exact support varies | Often low when built into a device; organizational integration varies | Low after setup |
| FIDO2 security key | High; hardware performs origin-bound public-key authentication | Private key stays on the key | Low for the sign-in itself; loss and replacement require protected recovery | Moderate to high unless backup keys and recovery procedures are provided | Supported browsers and identity providers; verify compatibility | Hardware purchase and lifecycle management | Low to moderate; the key must be present |
CISA states that “The only widely available phishing-resistant authentication is FIDO/WebAuthn authentication.” It also says, “Any MFA is better than no MFA.” That makes SMS or push a worthwhile interim control, not the target state for valuable accounts.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What to use instead of text-message codes
Choose passkeys for everyday sign-in
Passkeys use the FIDO2/WebAuthn standard. Your device creates a public/private key pair; the service stores the public key, while the private key remains protected by the device. During sign-in, the browser checks the website origin before asking the authenticator to sign, so a look-alike domain cannot obtain a valid assertion for the real service.
Passkeys can be stored on a phone, computer or supported password manager and may synchronize within that provider’s ecosystem. Check the identity provider’s documented browser and operating-system support, and register an additional recovery authenticator before removing an older one.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Use FIDO2 security keys for high-value or administrative access
A physical FIDO2/WebAuthn key is a strong choice for administrators, remote-access accounts, email, VPN and other services whose compromise would affect many people. Keep a second key enrolled in a separate secure location. Confirm compatibility with the account, browser and operating system before buying or issuing keys.
Use number matching as a transitional control
If an organization cannot deploy phishing-resistant authentication immediately, enable number matching for push approvals and restrict legacy sign-in paths. It helps against indiscriminate push bombardment, but an AiTM proxy can still relay the transaction, so it should not be described as equivalent to a passkey or security key.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How organizations should deploy phishing-resistant MFA
- Prioritize the accounts that unlock other accounts. Start with administrators, identity-provider administrators, remote access, email, VPN, developer infrastructure and financial systems.
- Enforce the method with conditional access. Require FIDO2/WebAuthn or passkeys for the priority applications and block legacy protocols that cannot enforce the policy. Provider labels and policy paths differ, so follow the identity provider’s current administrative guide.
- Protect enrollment. Use secure onboarding, verified identity proofing and controlled devices. Microsoft specifically recommends passkeys or FIDO2, conditional-access enforcement, secure onboarding and temporary access passes.
- Design recovery before rollout. Issue backup keys or a second passkey, limit who can reset authenticators, make recovery credentials time-bound and require strong identity proofing for replacement.
- Train for prompts and domains. Tell users never to approve an unsolicited request, and teach them to verify the domain and context rather than trusting a familiar logo or a number shown in a prompt.
- Monitor and revoke. Alert on unusual locations, new devices, repeated denials, new authenticator enrollment and forwarding-rule changes. After suspected compromise, revoke active sessions and rotate credentials according to the identity provider’s incident playbook.
What individuals should do today
- Turn on MFA immediately if an account offers none; CISA’s guidance is that any MFA is better than no MFA.
- For important accounts, replace SMS or ordinary push with a passkey or FIDO2 security key when the service supports it.
- Keep phone-carrier and email accounts separately protected, because they can be used to recover other accounts.
- Deny and report prompts you did not initiate. Repeated prompts are a warning sign, not a reason to approve one.
- Review active sessions, registered authenticators, recovery methods and email forwarding rules after an unexpected sign-in.
If you suspect a session was stolen
- Use a known-clean device to change the password and revoke all active sessions in the identity provider’s security settings.
- Remove unfamiliar passkeys, security keys, authenticator registrations, recovery addresses and phone numbers.
- Contact the mobile carrier if a SIM swap is possible and secure the email account used for recovery.
- Review sign-in logs, mailbox rules, cloud sharing and newly created OAuth or application consents.
- For a work account, notify the security or IT team immediately so they can apply tenant-wide session revocation, token invalidation and credential rotation.
Exact menu names and revocation behavior vary by identity provider. The key response is to invalidate the stolen session, not merely to change the password while leaving existing tokens active.
The bottom line
2FA is not a single security level. Relayed codes, push approvals and phone-number attacks can let criminals complete the same second-factor step you see and then take the resulting session. Use MFA rather than no MFA, but move high-value accounts to passkeys or FIDO2 security keys, and protect enrollment and recovery as carefully as the sign-in itself. Microsoft summarizes the direction plainly: “Traditional MFA is no longer enough—phishing-resistant MFA is the new baseline.”
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

