A clear sign is when account takeover rates rise while 2FA appears in only a small share of transactions. Another indicator is a channel with fast checkout, strong volume, and weak step-up coverage despite repeated abuse patterns. That combination suggests the control is not aligned to actual risk. Teams should look for disproportionate ATO losses, low challenge rates, and repeated compromise in the same customer journey.
What underuse looks like in a fraud-prone channel
Underuse usually shows up as a control that is technically available but rarely invoked where abuse is concentrated. In practice, that means the channel keeps absorbing fraud losses, repeat compromise, or suspicious login behavior while challenge rates stay low, especially in flows designed for speed or conversion. The gap is not just volume, it is mismatch: the control is not being applied where the risk is highest.
Look for journeys where users can complete high-value actions with little or no step-up, even after prior abuse patterns have been established. When fraud clusters around the same entry point, device pattern, or customer segment, weak 2FA coverage is often a signal that the channel has optimised for convenience faster than it has adapted to abuse. The risk is usually visible in the ratio between attack pressure and control activation.
- High account takeover or fraud losses with low 2FA challenge frequency
- Repeated abuse in the same channel or step in the journey
- Strong transaction volume with little step-up for risky events
- Fast checkout or low-friction flows that bypass stronger authentication too often
Channel signals that point to weak step-up coverage
The most useful signals are behavioral, not just policy-based. If the channel sees repeated suspicious logins, credential-stuffing style patterns, or chargeback-linked abuse, but 2FA is still only triggered for a small minority of sessions, the control is probably under-deployed. That is especially true when the same control is used elsewhere in the product but not in the fraud-prone path.
A second indicator is uneven protection across the journey. For example, 2FA may exist at enrollment or password reset, yet the fraud-prone action, such as payout change, new payee creation, or account recovery, remains weakly protected. In those cases, the channel is not “without 2FA”; it is underusing it where the security decision actually matters.
For practitioners who want a broader identity lens on recurring fraud pressure, NHIMG’s Ultimate Guide to NHIs is useful on governance, lifecycle, and access control patterns that often expose weak authentication coverage. Case-level evidence also helps, including the Uber Breach, where MFA fatigue and social engineering turned weak challenge design into access abuse, and the Microsoft Midnight Blizzard breach, which shows how legacy access paths without strong authentication remain attractive to attackers.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-01 — Identity Management, Authentication and Access | This channel problem is about whether authentication is applied where abuse risk is highest. |
| Recommendation — Align step-up authentication to the riskiest customer journeys and high-impact actions. | ||
| CIS Controls v8 | 5.1 — Establish and Maintain an Inventory of Accounts | Weak 2FA coverage is often easiest to find where account protection and usage are uneven by path. |
| Recommendation — Review account protection coverage by channel and prioritize stronger controls where abuse clusters. | ||
Practitioner Guidance
What to verify: Compare challenge rate, fraud rate, and conversion rate at the exact step where abuse occurs. If 2FA is concentrated in low-risk flows but absent from the fraud-heavy path, the problem is prioritisation, not adoption.
Decision rule: If a channel generates disproportionate ATO or fraud losses, treat low 2FA challenge coverage there as a control-design gap and raise step-up coverage before tuning minor UX friction elsewhere. Do not wait for a perfect fraud score if the same journey is already being exploited repeatedly.
What good looks like: Risky actions should trigger step-up at a rate that is visibly higher than the channel average, and repeated abuse should cause the challenge policy to tighten, not remain static. The target state is a channel where authentication strength tracks observed exposure.
Practitioner takeaway: Underuse is easiest to miss when the channel feels successful, but fraud-prone journeys should prove that 2FA is being applied selectively and aggressively enough to match real attack pressure, not merely present somewhere in the product.
Related resources from NHI Mgmt Group
- What breaks when merchants rely only on CVV and two-factor authentication to stop friendly fraud?
- Why does SIM swap fraud bypass SMS-based two-factor authentication so easily?
- What are the signs that a phishing kit is designed to bypass two-factor authentication rather than just collect passwords?
- What is the difference between two-factor authentication and MFA in practice?