Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Multi-factor authentication (MFA) reduces account-takeover risk, but it is not a universal defense. Attackers can trick people into handing over codes, relay credentials through fake login pages, hijack an authenticated session, or take control of the phone or device that receives an MFA challenge. The practical answer is stronger, phishing-resistant authentication combined with device, password, patching and recovery controls.

What MFA protects—and what it does not

MFA requires more than one proof of identity, such as a password plus a one-time code, approval prompt, hardware key or biometric unlock. That extra proof can stop an attacker who has only stolen a password. It does not automatically protect the factor itself, the endpoint on which authentication occurs, or an already-authenticated session.

Dave Lewis, Global Advisory CISO at 1Password, summarized the limitation in his August 21, 2024 Dark Reading commentary: “MFA is an important solution. It can certainly help. But it is by no means the silver bullet that will save the day.” His examples are useful threat scenarios, not measurements of how often each attack occurs.

How attackers get around MFA

Social-engineering the code or approval

An attacker who has a victim’s password may pose as a help-desk worker, bank employee or colleague and ask for the verification code. The attacker then enters the code at the genuine service while the victim reads it aloud or types it into a chat. Push-approval attacks use the same human weakness: repeated prompts can cause a user to approve one simply to stop the interruptions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Fake login pages and adversary-in-the-middle relays

A lookalike site can collect a password and manually entered MFA code, then relay both to the real service. A more capable proxy can also capture a session cookie after successful authentication. The user may complete MFA correctly while the attacker obtains an authenticated session.

Lewis also notes that malicious Wi‑Fi hotspots and Domain Name System (DNS) spoofing can redirect users to fake login pages that capture MFA codes and session tokens. MFA does not verify that the page displaying the prompt is the intended verifier.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

SIM swapping and phone-number takeover

SMS codes depend on control of a telephone number. In a SIM-swap attack, criminals persuade a carrier to move the number to a SIM or eSIM they control, causing future codes to arrive to them. This is a compromise of the delivery channel, not a failure of the user’s password.

Compromised devices and active sessions

Malware, a stolen unlocked device, a malicious browser extension or remote-support fraud can expose credentials, intercept prompts or use a session that is already authenticated. MFA cannot repair a compromised endpoint or revoke every session an attacker has acquired; those require endpoint security, session controls and incident response.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Why “MFA” does not tell you whether authentication resists phishing

MFA is a category, not a security rating. NIST’s Digital Identity Guidelines: Authentication and Authenticator Management (SP 800-63B-4, July 2025) says that manually entered one-time passwords and out-of-band authenticator outputs are not phishing-resistant. An impostor can relay the output to the real verifier because the code is not bound to the particular session or verifier.

Phishing resistance means the protocol prevents disclosure of a secret or valid authentication result to an impostor verifier without depending on the user to recognize the deception. NIST identifies two approaches: channel binding and verifier-name binding. Channel binding ties the authentication to the protected communication channel. Verifier-name binding makes the authenticator use the legitimate service’s authenticated domain name, so a lookalike domain cannot obtain a valid response.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

NIST gives WebAuthn, used by FIDO2 authenticators, as the familiar verifier-name-binding example. The authenticator selects a secret based on the authenticated domain name. A copied login page therefore cannot simply collect a reusable code and replay it at the genuine site.

Authentication methods compared

Method Phishing resistance Relay exposure Operational considerations
SMS one-time code Not phishing-resistant An attacker can capture and relay the code; SIM swapping can redirect it Easy to deploy, but depends on the mobile-number channel
Manually entered authenticator-app OTP Not phishing-resistant under NIST SP 800-63B-4 A fake site can collect the current code and relay it More dependable than SMS in some environments, but still relies on user vigilance
Out-of-band approval or code Not phishing-resistant when the output is manually entered or can be relayed Attackers can socially engineer an approval or relay the output Use clear transaction details and rate limits; do not treat every prompt as legitimate
WebAuthn/FIDO2 security key or passkey Designed for phishing resistance through verifier-name binding The authenticator response is bound to the legitimate verifier rather than a lookalike site Confirm service support, enrollment options and recovery paths; implementation and assurance level still matter

The table describes protocol properties, not a guarantee that every deployment has identical assurance. Configuration, account-recovery procedures, endpoint condition and service support can change the practical outcome.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What NIST’s assurance levels require

AAL2

NIST SP 800-63B-4 requires an AAL2 verifier to offer at least one phishing-resistant authentication option. “Offer” does not mean every AAL2 transaction must use that option; an organization may still permit another compliant method unless its own policy requires phishing-resistant use.

AAL3

AAL3 requires phishing-resistant cryptographic authentication. NIST treats key exportability differently at this level, including prohibiting syncable authenticators at AAL3. Do not assume that a passkey’s presence alone establishes AAL3 assurance.

Passkeys and syncable authenticators: stronger, with deployment trade-offs

Passkeys commonly use WebAuthn/FIDO2 and can provide verifier-name binding. NIST’s April 2024 supplement on syncable authenticators identifies recovery and cross-device support as benefits when these systems are implemented correctly. A user may be able to restore an authenticator through an approved ecosystem rather than lose access when a device is replaced.

Those benefits do not make every passkey deployment equivalent. Review where keys are stored, how they are synchronized, what recovery can override, and which assurance level the service needs. For systems requiring AAL3, syncable authenticators are not permitted under SP 800-63B-4.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Defense in depth: controls that make MFA useful

Offer a phishing-resistant option

  • Enable WebAuthn/FIDO2 security keys or passkeys for services that support them.
  • Keep a documented, protected recovery method; recovery should not silently downgrade the account to a weaker factor.
  • Verify that critical applications support the authenticator and account lifecycle you need before making it mandatory.

Check device posture

  • Allow sensitive access only from expected, managed or otherwise trusted devices where practical.
  • Require current security patches and detect compromised or noncompliant endpoints.
  • Use session revocation and reauthentication after high-risk events such as device loss, password reset or suspicious location changes.

Manage passwords and secrets

  • Use a unique password for every service so one breach does not unlock another account.
  • Use a reputable password manager to generate and store those credentials.
  • Prioritize phishing-resistant authentication for the accounts that can reset other accounts or reach sensitive data.

Design safer user and help-desk workflows

  • Tell users never to disclose a one-time code or approve an unexpected prompt.
  • Train support staff to verify identity through an independent channel before changing MFA factors.
  • Alert on unusual enrollment, recovery, SIM changes, impossible travel, mass prompting and new-session activity.

A practical rollout checklist

  1. Inventory the account paths. Identify administrators, remote access, email, financial systems and any service that can reset credentials.
  2. Classify the available factors. Record whether each option is SMS, OTP, out-of-band approval or WebAuthn/FIDO2, rather than labeling them all simply “MFA.”
  3. Enable phishing-resistant authentication. Start with privileged and recovery-capable accounts, then expand to other users as service support and enrollment allow.
  4. Protect recovery. Test lost-device, replacement-device and employee-offboarding procedures; ensure recovery does not become the easiest bypass.
  5. Enforce endpoint and password controls. Check patch status and device trust, and require unique managed passwords where passwords remain in use.
  6. Monitor and rehearse response. Establish alerts, revoke sessions after suspected compromise and practice help-desk escalation for social-engineering attempts.

Can MFA be bypassed?

Yes, depending on the factor and the attack. SMS and manually entered OTPs can be relayed; users can be persuaded to approve requests; phone numbers, devices and active sessions can be compromised. Phishing-resistant cryptographic authentication blocks the common fake-site replay path, but it still belongs inside a program that covers endpoints, recovery, passwords, patching and monitoring.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.