MFA code harvesting is a phishing technique that tricks a user into revealing a one-time authentication code. Attackers use the code to complete login or recovery flows in real time, which defeats the protection of multi-factor authentication if the victim willingly shares the secret.
What MFA Code Harvesting Is and Why It Works
MFA code harvesting is a real-time phishing method that exploits user trust rather than breaking the authenticator itself. The attacker’s goal is to obtain a valid one-time code while it is still usable, then relay it into a live login or recovery flow before the code expires.
This makes the technique especially effective against MFA designs that still rely on human entry of short-lived secrets. Once the victim reveals the code, the attacker does not need to guess the password again, they simply complete the authentication step that the victim just authorized.
How MFA Code Harvesting Happens in Practice
The attack usually begins with a believable sign-in prompt, help-desk message, or account-recovery page that mimics a legitimate service. The target is guided into entering a code they received by SMS, authenticator app, voice call, or email, then the attacker immediately reuses it in the real session.
Code harvesting often works best when users are in a hurry, expect a legitimate login challenge, or are conditioned to approve support requests. It can also be paired with adversary-in-the-middle phishing, where the attacker relays the authentication flow in real time so the victim sees a normal-looking login experience.
Security Implications of Code Harvesting
Because the code is valid at the moment it is stolen, the attack bypasses the practical protection that MFA is supposed to provide against password compromise alone. That is why phishing-resistant methods are preferred for higher-risk environments, and why guidance such as NIST SP 800-63 Digital Identity Guidelines places strong emphasis on authenticators that resist interception and replay.
Code harvesting also exposes a broader weakness in recovery and reset flows. If an attacker can persuade a user to reveal a code during sign-in or account recovery, the same social-engineering pattern may be used to seize sessions, reset credentials, or pivot into additional services tied to the account.
How Organisations Reduce MFA Code Harvesting Risk
The most reliable defensive direction is to reduce reliance on shareable one-time codes and move toward phishing-resistant authentication. NHIMG’s Passwordless and Passkeys Guide explains why passkeys and FIDO2 sharply reduce the value of harvested codes, and the MFA Guide covers the common bypass patterns defenders need to understand.
Operationally, organisations should harden sign-in, help-desk, and recovery journeys so they do not depend on user judgment at the moment of authentication. The Workforce Identity Security Guide is useful here because it treats phishing-resistant MFA, recovery, and session theft as part of the same control surface.
Well-known breaches show why this matters. The Twilio 0ktapus breach 2022 and Uber Breach both illustrate how social engineering around MFA can turn a defensive layer into an access path.
Examples of MFA Harvesting Attacks and Failure Modes
One recurring failure mode is simple relay of a one-time code into a legitimate sign-in page. Another is fatigue or pressure-based social engineering, where the victim is convinced to comply with a request that appears urgent, routine, or support-related. In both cases, the attack succeeds because the user becomes the unwitting final step in the authentication chain.
Real incidents also show that MFA code harvesting is often part of a wider intrusion playbook, not an isolated trick. Microsoft Midnight Blizzard breach and Change Healthcare breach 2024 show how access obtained through weak or bypassed authentication can cascade into much larger compromise. CitrixBleed exploitation 2023 is a useful adjacent example because it demonstrates the same outcome, attackers reaching a session without being stopped by MFA.
In modern environments, harvested codes may also be used to unlock downstream OAuth or session-token abuse. CoPhish OAuth Token Theft via Copilot Studio shows how phishing can move from code capture to token theft when the attacker targets a live authentication workflow.
Risk and Threat Considerations
MFA code harvesting is dangerous because it turns the human factor into the bypass path. Even strong MFA can fail if the organisation allows reusable, shareable or relayable codes to be entered into a convincing phishing flow.
Failure mechanism: The attacker deceives the user into revealing a one-time code, then reuses that code immediately in the genuine authentication or recovery process before it expires.
Impact: The attacker can obtain account access, complete recovery, steal sessions, and move into internal systems or connected services with the victim’s authority.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, OWASP ASVS, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Defines phishing-resistant authenticators and recovery assurance for this login attack |
| Recommendation — Adopt phishing-resistant authenticators and stronger recovery assurance for accounts that face code-harvesting risk. | ||
| OWASP ASVS | V6 — Authentication | Covers authentication flows that must resist phishing and replay of one-time codes |
| Recommendation — Verify that authentication flows cannot be completed by relayed or harvested one-time codes. | ||
| MITRE ATT&CK | T1566 — Phishing | Code harvesting is a phishing technique that abuses user trust to obtain credentials or codes |
| Recommendation — Map observed code-harvesting activity to phishing tradecraft and tune detections for relay and impersonation. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle and management controls limit reuse and weak code-based factors |
| Recommendation — Manage authenticators so shared or replayable one-time codes do not remain an effective access path. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access control governance should reduce exposure from compromised authentication events |
| Recommendation — Restrict access paths and review account recovery controls that can be abused after code harvesting. | ||
Practitioner Guidance
Why practitioners should care: Treat code harvesting as an authentication-design problem, not just a user-awareness problem. If users can be coached into revealing a code, the authentication path is still too dependent on human judgment.
Governance implication: Prioritise phishing-resistant sign-in methods for high-value users and sensitive systems, and review recovery flows with the same scrutiny as primary login. Where SMS, TOTP, or other code-based factors remain in use, constrain their role and make the fallback paths harder to abuse.
Practitioner takeaway: The best control is to make stolen codes useless, not merely to ask users to be careful.
Related resources from NHI Mgmt Group
- What is the difference between passwordless MFA and one-time code MFA?
- How should security teams harden MFA against code-guessing attacks?
- Why do passwords, MFA, and passkeys fail to stop device code phishing?
- How should security teams handle device code phishing when users complete real Microsoft MFA?