2FA is failing when banned users can still create fresh accounts by changing phone numbers, spoofing identity checks, or obtaining a second SIM. Those workarounds show that the control is verifying a channel, not proving persistent user identity. If abuse continues despite SMS verification, the organisation needs stronger cross-linking and repeat-offender detection.
Why 2FA can still allow repeat account abuse
Two-factor authentication can be a real barrier to account takeover, but it does not automatically stop a determined abuser from returning with a new identity. If the sign-up or recovery flow still accepts a changed phone number, a reused device, or a weak verification step, the control is proving access to a channel rather than proving the same person has returned.
That distinction matters because abuse can continue even when the login step looks successful. The control may reduce opportunistic attacks while still leaving the organisation exposed to ban evasion, duplicate accounts, and repeat fraud. In practice, the question is whether the system can link new registrations back to prior abusive activity, not whether it can deliver a one-time code.
For phishing-resistant alternatives and the limits of SMS-based protection, MFA Guide and NIST SP 800-63 Digital Identity Guidelines are useful references for the difference between channel verification and stronger authenticator assurance.
Which failure signals show the control is too weak
The clearest sign is repeat misuse that survives a fresh verification path. If banned users can register again after swapping numbers, using a second SIM, or passing a basic identity check that can be spoofed, the organisation is seeing an identity linkage failure, not just an authentication failure. SMS verification often breaks down here because the phone number is easy to replace and the number itself is not a durable identity anchor.
Another warning sign is when enforcement is local to one account instead of global to the actor. A user can be blocked on the original account, then immediately return through a new account, new email address, or new phone number without tripping a cross-account control. That usually means the abuse prevention design lacks correlation across registrations, recovery events, devices, and prior enforcement history.
The practical lesson is visible in 23andMe credential stuffing 2023 and Twilio 0ktapus breach 2022, where authentication was bypassed through weak human and channel-based trust assumptions rather than a single broken password alone.
What stronger defenses need to add
Once repeat abuse is visible, the control objective has to move from login verification to durable abuse resistance. That means correlating users across identifiers, detecting reused devices and recovery paths, and treating account creation, number change, and reset events as part of the same trust workflow. Where possible, use stronger sign-in methods that are harder to re-enroll under a new identity, and pair them with risk-based step-up and repeat-offender review.
Stronger controls usually need both prevention and detection. Prevention limits how easily an abuser can re-establish access, while detection looks for patterns such as repeated SIM changes, rapid re-registration after bans, and multiple accounts sharing the same recovery or payment footprint. Without that correlation, 2FA can remain a speed bump while abuse simply shifts to the next phone number or verification route.
That is why Passwordless and Passkeys Guide and Workforce Identity Security Guide are useful even for a customer-abuse problem: both show how stronger authenticators and recovery design reduce the chance that a new account can simply replace an old one.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST SP 800-63, CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | 2FA failure is an authentication weakness affecting user verification. |
| IA-5 — Authenticator Management | Repeat abuse often exploits weak authenticator recovery and replacement flows. | |
| IA-8 — Identification and Authentication (Non-Organizational Users) | Account abuse in customer-facing systems depends on external-user identity assurance. | |
| Recommendation — Strengthen user authentication and require higher-assurance authenticators for risky re-entry. Tighten authenticator lifecycle controls for reset, replacement, and recovery. Apply stronger identity proofing and authentication for external-user enrollment. | ||
| NIST SP 800-63 | IAL — Identity Assurance Level | Persistent identity proofing is central when users can re-register after bans. |
| AAL — Authenticator Assurance Level | 2FA strength depends on authenticator assurance, not just code delivery. | |
| Recommendation — Raise assurance requirements for enrollment and recovery when repeat abuse is a concern. Use a higher authenticator assurance level where SMS-based verification is being bypassed. | ||
| CIS Controls v8 | CIS-5 — Account Management | Abuse recurrence signals weak lifecycle controls across new and recovered accounts. |
| CIS-6 — Access Control Management | Persistent abuse shows access decisions are not tied to durable identity signals. | |
| Recommendation — Centralise account lifecycle review and flag repeated creation patterns for investigation. Enforce stronger access decisions for re-enrolled users and high-risk account changes. | ||
| OWASP ASVS | V6 — Authentication | The issue is whether authentication actually resists re-entry and bypass. |
| V8 — Authorization | Repeat offenders exploit gaps between login success and what the account may do next. | |
| Recommendation — Require phishing-resistant and recovery-safe authentication for sensitive user flows. Restrict high-risk actions until the account’s trust state is revalidated. | ||
Practitioner Guidance
What to verify: Test the full abuse path, not just the login step. If a banned user can complete registration, recovery, or number change with fresh credentials, the control is not stopping re-entry and should be treated as incomplete.
What to prioritise: Cross-linking signals usually matter more than another checkbox at sign-in. Correlate phone number, device, recovery method, payment instrument, and previous enforcement actions before relying on the 2FA result as evidence of a new, legitimate user.
Decision rule: If abuse persists after SMS verification, move to a stronger authenticator and an abuse-detection workflow together. Treat the control as insufficient whenever the same actor can rapidly re-establish a new account without triggering review.
Practitioner takeaway: The key question is not whether 2FA works at the point of entry, but whether it prevents the same abusive actor from coming back under a different wrapper. If it does not, the missing control is identity continuity and repeat-offender detection.
Related resources from NHI Mgmt Group
- What are the signs that an organisation’s identity security baseline is not enough to stop account takeover?
- What are the signs that login controls are not strong enough to stop account takeovers?
- What are the signs that early account monitoring is not working well enough to stop fraud?
- What breaks when 2FA is bypassed through account recovery abuse?