Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A stolen password can still open an account if there is no multi-factor authentication (MFA), if an attacker can also obtain or defeat the additional factor, or if the password is reused on a service with weaker protection. But a password alone does not automatically bypass MFA: when an attacker cannot provide the second factor, MFA can block access.

Why a stolen password may still work

There are several ways an attacker could get past a sign-in that appears to require more than a password. Which apply depends on the account’s settings and the attacker’s access.

  • The account has no MFA. A password may be enough when the service does not require another sign-in factor.
  • The attacker has the other factor, too. For example, a phishing attempt may capture both a password and a one-time code.
  • The factor can be manipulated or intercepted. Push-bombing attacks send repeated sign-in prompts in the hope that a user will approve one. SIM swapping or other telecommunications attacks can put SMS or voice codes at risk.
  • A reused password works elsewhere. Credential stuffing means trying username-and-password pairs obtained from one system on other services. A password exposed in one breach may therefore put another account at risk, especially if it has weaker sign-in protections.

CISA says MFA makes access harder when an attacker has only the password and cannot provide the additional factor. Its guidance does not mean that every MFA method is equally resistant to phishing or other attacks. CISA’s October 2022 fact sheet on phishing-resistant MFA explains the distinction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the type of MFA changes the risk

MFA adds a hurdle, but the method matters. Some methods are easier to phish or intercept than others, and an account’s recovery process may use a weaker method than its regular sign-in.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
  • SMS or voice codes: CISA says SMS-based MFA is not phishing-resistant and recommends against it for highly targeted accounts. Telecommunications attacks can also put these codes at risk.
  • Authenticator-app codes: CISA considers these better than SMS in its guidance, but they can still be captured through phishing.
  • Push approvals: Repeated prompts can pressure or confuse a user into approving a sign-in they did not initiate. Do not approve an unexpected prompt.
  • FIDO authentication: CISA describes FIDO-based authentication as phishing-resistant. A supported hardware security key is its strongest option where feasible; passkeys are an acceptable alternative.

For valuable accounts, CISA recommends FIDO authentication, including for Microsoft, Apple, and Google accounts. A security key helps only if the service supports it and the user enrolls it; adding one does not undo access an attacker may already have. CISA’s mobile communications guidance, current as of December 18, 2024, recommends hardware-based keys where feasible and recognizes passkeys as an alternative.

What to do if you think someone can access your account

Use the affected service’s official compromised-account recovery process. Recovery steps and their order differ by service, so there is no universal sequence that applies to every account.

Rank #2
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Follow the service’s official recovery instructions. Use its own website or app, rather than links in an unexpected message.
  2. Change the exposed password. Also change it anywhere else you reused it; use a different password for every account.
  3. Review the account’s active sessions, recovery methods, and MFA options. Remove access or methods you do not recognize, following the service’s instructions.
  4. Strengthen sign-in protection. Where supported, enroll a passkey or hardware security key. If you use SMS as a fallback, consider removing it after setting up a stronger method—but keep a recovery option you can safely use.

Choose long, random, unique passwords. A password manager can generate and store them, and some managers can flag weak, reused, or exposed passwords. CISA recommends using one in its password guidance. Even with a stronger MFA method enabled, check the service’s recovery options: CISA warns that some services may still use SMS during recovery.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What MFA does—and does not—guarantee

MFA can stop an attacker who has a password but cannot satisfy the account’s additional check. It is not a guarantee if the account lacks MFA, the attacker has another factor, or a weaker factor or recovery route can be abused. CISA’s account of an organizational compromise involving administrator accounts without MFA illustrates why unprotected access matters; it is not evidence about the security settings of any particular consumer account. The February 2024 CISA and MS-ISAC advisory describes that incident and recommends phishing-resistant MFA for organizations.

Rank #3
Sale
Password Safe
  • Requires 3 "AAA" batteries (included)
  • Unit auto-locks for 30 minutes after 5 consecutive incorrect PINs

The practical response is to treat an exposed password as a risk across every service where it was reused, follow the affected service’s recovery process, and strengthen both routine sign-in and fallback methods.

Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.