The bottom line: Inadequate MFA implementation and new attack vectors (prompt bombing, session hijacking, AI-powered phishing) jeopardize authentication; protection requires consistent rollouts, passwordless methods, and FIDO standards.
Multifactor authentication (MFA) is frequently implemented poorly and thus provides less protection than possible. At the same time, current attacks — from AI-powered phishing campaigns to Okta breaches — show that even established implementations have vulnerabilities.
The security benefits of multifactor authentication are theoretically well known, but practical implementation is inconsistent and fragmented. According to a 2025 JumpCloud survey, 87 % of larger enterprises regularly deploy MFA methods, but only about one-third of smaller firms do the same. Particularly critical: Cisco found that 87 % of respondents regard phishing-resistant MFA as necessary, but fewer than 20 % have implemented such procedures enterprise-wide.
Attackers exploit weaknesses on multiple fronts. The most common attack scenarios include prompt bombing (repeated authentication requests), session hijacking, man-in-the-browser attacks, consent phishing, SIM swapping, and evil proxy attacks that intercept authentication codes in real time. Particularly noteworthy are AI-powered phishing campaigns that extract cloud keys and SSH credentials, as well as attacks leveraging developer tools like Claude Code. The 2023 Okta breaches also demonstrate that even established providers are vulnerable — the breaches led to theft of GitHub source code, compromised supply chains, and unauthorized access to support portals.
The core problem lies in the complexity of modern authentication flows. Users access systems via web portals, mobile apps, APIs, or AI interfaces; they connect locally, over VPN, with different operating systems and browsers. This diversity creates gaps in access policies and enables attackers to intercept authentication codes at numerous attack points — from the browser through weak account recovery mechanisms to legacy apps not protected by MFA.
Countermeasures: Passwordless authentication is gaining importance and is being driven forward by requirements from Google and Microsoft. Relevant standards such as FIDO biometrics substantially reduce attack surfaces. Organizations should also maintain continuous vigilance in MFA testing and configuration, close policy gaps, and prioritize phishing-resistant technologies. Frameworks from actors such as the FIDO Alliance, Cisco Duo, and RSA provide concrete implementation guidance.
Source: www.csoonline.com · Published 29 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.