One-time codes improve access control, but they still leave gaps against phishing, malware, and man-in-the-middle attacks. If an attacker captures the code in real time, the protection collapses. SMS delivery also depends on mobile carriers and phone access, which introduces recovery and interception risks. For sensitive accounts, code-based MFA is a weaker control than hardware-backed authentication.
Why one-time codes stop being enough on high-value accounts
One-time codes improve access control, but they still leave gaps against phishing, malware, and man-in-the-middle attacks. If an attacker captures the code in real time, the protection collapses. SMS delivery also depends on mobile carriers and phone access, which introduces recovery and interception risks. For sensitive accounts, code-based MFA is a weaker control than hardware-backed authentication.
The core problem is that a one-time code usually proves possession at a single moment, not a durable, phishing-resistant binding between the user, the device, and the login session. That means it can be replayed quickly enough to satisfy an attacker-controlled sign-in flow, especially when the victim is tricked into entering the code into a fake site or proxy.
SMS codes are especially fragile because they rely on telecom delivery and a reachable phone number. If the number is swapped, forwarded, intercepted, or simply unavailable, the account recovery path becomes part of the attack surface rather than a safety net. High-value accounts need authentication that resists interception and is tied to the legitimate origin of the sign-in request.
What attack paths remain open when codes are the only second factor?
Phishing kits and real-time proxy attacks are the most obvious failure mode, because they can harvest a valid code and immediately use it before it expires. Malware on the endpoint can also capture a code from the browser, notification stream, or SMS inbox. In practice, the control is only as strong as the attacker’s ability to observe or relay that short-lived secret.
For this reason, organisations that want stronger MFA should treat hardware-backed methods, passkeys, or other phishing-resistant authenticators as the benchmark for high-value accounts. Guidance on phishing-resistant MFA shows why relay, fatigue, and token theft defeat weaker factors, while Twilio 0ktapus breach 2022 illustrates how SMS phishing can be operationalised at scale.
Account takeover risk also increases when one-time codes are used as the last barrier for privileged or externally reachable systems. A stolen code can unlock not just a mailbox or portal, but password reset flows, recovery options, and downstream authorisations that were never meant to be exposed to a transient attacker.
What stronger authentication changes for sensitive user accounts?
Stronger authentication changes the failure model from “can the attacker read a code in time?” to “can the attacker satisfy a cryptographic challenge bound to the legitimate device and origin?” That materially raises the cost of phishing and interception. It also reduces dependence on brittle recovery channels, which matters when account access itself protects payments, admin tools, customer data, or corporate control planes.
For sensitive accounts, the right comparison is not OTP versus no OTP, but OTP versus phishing-resistant methods that make real-time relaying ineffective. The MFA Guide is useful here because it separates SMS, authenticator-app codes, and security keys by how well they resist interception, and it helps teams see why “MFA enabled” is not the same as “MFA fit for purpose.”
Where organisations support break-glass access, the recovery path must be designed separately from everyday user sign-in. The Break-Glass and Emergency Access Account Guide is relevant because emergency access often becomes the fallback after a lost phone, MFA outage, or lockout, and that fallback needs tighter monitoring than ordinary login flows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | One-time codes can be intercepted or relayed in real time. |
| NHI-07 — Long-Lived Secrets | SMS and reusable recovery paths increase exposure when code delivery is compromised. | |
| NHI-10 — Human Use of NHI | Human handling of codes and recovery steps creates interception risk. | |
| Recommendation — Require phishing-resistant authentication for high-value accounts. Minimise reliance on reusable recovery factors and rotate exposed credentials quickly. Reduce human-mediated secret handling in authentication flows. | ||
| NIST SP 800-63 | Digital Identity Guidelines | The topic is authentication assurance and phishing resistance for user accounts. |
| Recommendation — Use phishing-resistant authenticators at higher assurance levels for sensitive accounts. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | High-value user accounts need stronger sign-in controls than codes alone. |
| IA-5 — Authenticator Management | Code-based MFA depends on secure issuance, delivery, and lifecycle control. | |
| IA-9 — Identification and Authentication (Non-Organizational Users) | The account-risk pattern also applies when external user accounts are high value. | |
| Recommendation — Enforce stronger authenticators for organizational user access. Manage authenticators with tight issuance, rotation, and revocation. Apply stronger authentication controls to externally managed accounts. | ||
| OWASP ASVS | V6 — Authentication | The question concerns whether OTP-only authentication is sufficient. |
| V10 — OAuth and OIDC | High-value account access often depends on federation and sign-in assurance. | |
| Recommendation — Verify phishing-resistant authentication requirements for sensitive user flows. Validate federated sign-in assurance and resistance to token relay. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication and Access Control | The issue is whether the access control strength matches the account value. |
| Recommendation — Strengthen authentication controls where account impact is high. | ||
Practitioner Guidance
What to verify: If an account can trigger privileged actions, recovery workflows, financial actions, or admin changes, verify that a phishing-resistant factor is available and actually enforced for that population. Do not assume that an SMS or app code meets the bar simply because it is technically “multi-factor.”
Decision rule: If the account is high-value, internet-exposed, or used to administer other systems, move away from one-time codes as the primary control and require a hardware-backed or equivalent phishing-resistant method. Keep code-based MFA only where the blast radius is modest and the residual risk is acceptable.
What practitioners underestimate: The weak point is often not the login prompt itself, but the recovery chain around it, including phone access, carrier dependency, and support-led resets. Those paths deserve the same scrutiny as the initial authentication method.
Practitioner takeaway: One-time codes are useful as a convenience layer, but high-value accounts need authentication that survives real-time phishing and session relay, not just a second box to type into.
Related resources from NHI Mgmt Group
- What breaks when organisations rely on static watermarks for protecting high-value documents?
- What breaks when organisations rely on one-time identity checks?
- What breaks when organisations rely on one-time AI red teaming instead of continuous retesting?
- What breaks when organisations rely on user judgment alone to protect sensitive data in AI prompts?