COMMENTARY: A great many enterprises rolled out multi-factor authentication (MFA) and Auth apps over the past year and felt that they had made a meaningful leap forward.And, compared to passwords alone, they did. MFA and Auth apps raised the bar. But attackers adapted faster than most security roadmaps.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]Today, many of the most damaging breaches are not happening because the technology failed in the traditional sense. They happen because bad actors learned how to manipulate the people, workflows, and recovery processes surrounding MFA and Auth apps.That shift matters because it means organizations can do everything “right” by last year’s standards and still be exposed.LevelBlue’s latest research captures the change clearly. Attackers are increasingly moving away from classic phishing emails and malware and toward voice-based social engineering aimed directly at the identity layer, especially Okta and related support workflows.Instead of sending a malicious attachment, they call an employee, the help desk, or a contractor. They impersonate an executive, a locked out user, or a stressed employee who needs access immediately. Then they push for an MFA reset, a new device enrollment, a password reset, a push approval, or a one time code.If they succeed once, they can inherit trusted single sign-on (SSO) relationships across Microsoft 365, SharePoint, OneDrive, Salesforce, Slack, and HR systems. In other words, a single manipulated action against MFA or Auth Apps can become an enterprisewide breach.That’s why the industry needs to be honest about the existing state of MFA and Auth apps. They were an important step. They are just no longer sufficient against the modern identity playbook. And that playbook has become broader than many security teams realize.Today, there are at least 15 known methods attackers use to compromise MFA and Auth apps. They include help desk impersonation, vishing, push fatigue, adversary-in-the-middle phishing proxies, one-time passcode relay, and session cookie theft, among many others. While not every attacker uses every method, it’s now clear tht MFA and Auth apps now have many well-known bypass routes – and bad actors are using them every hour.By many accounts, 90% of all ransomware incidents the past two years involved compromising MFA or Auth apps. In March 2026, Microsoft said the Tycoon 2FA phishing-as-a-service operation had been linked to an estimated 96,000 distinct phishing victims, including more than 55,000 Microsoft customers. It’s stunning because it proves it’s not an edge case. It’s become industrialized, and it’s repeatable, scalable, and now profitable.Public reporting on major incidents over the past few years shows the same pattern. MGM Resorts and Caesars were hit in attacks tied to social engineering by Scattered Spider. Clorox alleged in court that attackers obtained password resets and MFA changes through service desk manipulation. Twilio’s breach used a fake Okta login flow that captured one-time codes in real-time. Qantas disclosed an attack on a third party customer service platform after a call center targeted identity processes. More recent reporting has also connected similar identity-first tactics to organizations including Stryker, Marks and Spencer, Hawaiian Airlines, Aflac, and Ingram Micro.None of this means enterprises were wrong to deploy MFA and Auth apps. It means the threat evolved. Security leaders should not feel foolish. They should feel informed. MFA and Auth apps were better than passwords alone, but many implementations still depend on shared secrets, reset paths, fallback methods, user approvals, and support desk interventions that attackers can manipulate. That’s exactly why CISA increasingly emphasizes phishing resistant MFA (ideally biometric) rather than just any MFA. The distinction now matters enormously.We think the likely end game for stopping identity-based attacks will become biometric assured identity. That category matters because it’s built to assure the actual identity of the person gaining access, not merely the possession of a phone, a code, or an Auth app.Biometric assured identity requires an active fingerprint, physical proximity, and the correct domain rather than a spoofed one. That combination changes the game: There’s no code to relay. No push message to approve. No easy fallback. No practical way for a bad actor on a phone call to talk a help desk into becoming the weak link. Identity gets established cryptographically, verified biometrically, and tied to the legitimate destination. That’s why this category represents more than just a patch for today’s attacks: it’s a durable architecture for the next many years of identity defense.Just as important, there’s also a strong economic case for biometric assured identity. Preventing a single major breach can save millions in direct response costs, legal exposure, downtime, cyber insurance consequences, and brand damage. At the same time, faster and more frictionless logins can improve employee productivity every day. That means the move beyond legacy MFA and Auth apps does not represent just a security upgrad: it’s often a financial upgrade as well. The organizations that understand this earliest will not just reduce risk. They will potentially spend less on cyber insurance, prevent incidents, and get more productive work from their people.Attackers are no longer trying only to steal passwords. They are attacking identity operations themselves. They are compromising MFA and Auth apps with methods that are now well-documented and widely-used. The organizations that still assume last year’s rollout solved the problem are looking at the wrong milestone.The industry’s real destination must become biometric assured identity because that’s the model designed to verify the real human, at the real moment, on the real domain, in real proximity. And that’s what it will take to finally make identity-based attacks stop working.Kevin Surace, chair, TokenCoreSC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
