TL;DR: Password-based MFA still leaves attackers room to phish, intercept one-time codes, and exploit prompt bombing because the password and second factors remain vulnerable, according to Beyond Identity. The security case for passwordless, phishing-resistant authentication is now operational, not theoretical, for IAM and NHI teams.
At a glance
What this is: This is an analysis of why password-based MFA still fails when the password and second factors remain phishable, intercepted, or fatigue-driven.
Why it matters: It matters because IAM teams that treat MFA as sufficient can still leave human and machine access exposed to account takeover paths that bypass the intended control.
By the numbers:
- Compromised credentials are the source of three out of every five attacks, according to Verizon's 2021 Data Breach Investigations Report cited by Beyond Identity.
Context
Password-based MFA adds a second step to login, but it still depends on factors that attackers can phish, intercept, or nudge users into approving. In practice, that means the control reduces risk without removing the underlying trust problem in human authentication.
For IAM teams, the issue is not whether MFA exists, but whether the factor pair is resistant to real-world attack paths such as phishing, SIM swapping, intercepted passcodes, and prompt bombing. That distinction matters just as much for workforce identity as it does when privileged access is the target.
Key questions
Q: What breaks when MFA is configured with weak, phishable factors?
A: Weak factors such as SMS codes, OTP apps, or push-based approvals can satisfy a policy checkbox while still leaving the environment open to phishing, man-in-the-middle, and push bombing attacks. That means the control may look compliant but fail under real attack conditions. Teams should test whether the factor actually binds the login to the user and target service.
Q: Why do phishable MFA factors still create account takeover risk?
A: Because the attacker does not need to defeat authentication in the abstract, only to exploit the weakest part of the factor chain. SMS, email OTP, and push approval can be intercepted, coerced, or fatigued into approval, especially when users expect glitches. A strong password does not compensate for a weak second factor.
Q: What are the warning signs that MFA prompt bombing is succeeding?
A: Look for repeated approval requests, users reporting notification fatigue, unusual device registrations after authentication, and accounts that see many failed or denied prompts before one success. Those signals show the attacker is using human reaction time as the bypass. They also indicate that the MFA design tolerates too much user ambiguity.
Q: Should organisations replace MFA with passwordless authentication?
A: Organisations should not treat this as a simple replacement question. MFA is still useful where passwordless is not yet available, but passwordless raises the security baseline by removing the password as the primary failure point. The right path is to use MFA as a bridge and passwordless as the destination.
Technical breakdown
Why password-based MFA remains phishable
Password-based MFA combines a password with a second factor such as SMS, email, push, or OTP, but none of those factors is inherently unphishable. If an attacker can intercept the message, coerce a push approval, or reuse stolen credentials, the second step becomes another weakness rather than a barrier. The control assumes the password is already known and the second factor is independently trustworthy, which is often false in real attacks. Practical deployments fail when the organisation treats MFA as a binary control instead of evaluating the resistance of each factor type.
Practical implication: Treat factor choice as a security decision, not a checkbox, and remove phishable second factors from high-risk access paths.
How MFA prompt bombing defeats user expectations
Prompt bombing works by exploiting notification fatigue. The attacker first obtains a password, then sends repeated approval requests until the user accepts one to make the alerts stop. This is not a technical bypass of the authentication stack so much as a manipulation of human behaviour around a weak factor. The article also shows why this works best where users already expect login problems, delayed codes, or inconsistent MFA prompts. In that environment, a malicious request looks like another routine annoyance rather than an obvious attack.
Practical implication: Assume user fatigue is part of the attack surface and remove approval-based factors from sessions that protect sensitive data or privileged access.
Why passwordless authentication changes the trust model
Passwordless authentication replaces shared, phishable secrets with cryptographic keys, local biometrics, and device-level checks. That changes the trust model from 'something the user knows plus something they may receive' to identity bound to a device and, where used, a local biometric or security posture signal. The important shift is not convenience alone. It is that authentication becomes resistant to interception and far less dependent on user response to a spoofable prompt. For IAM programmes, this is the point where phish resistance and usability start to align.
Practical implication: Use passwordless methods for access that would be material if phished, intercepted, or approved under fatigue.
Threat narrative
Attacker objective: The attacker wants to turn a phishable second factor into durable account access that bypasses the intended protection of MFA.
- Entry begins when an attacker obtains a password for an account protected by traditional MFA.
- Credential harvesting continues through phishing, SMS interception, SIM swapping, push abuse, or repeated OTP prompts that lead the user to approve access.
- Impact follows when the attacker registers a device or completes login and gains full account access, often to the wider network or sensitive resources.
Breaches seen in the wild
- Uber breach 2022: A contractor's stolen password and MFA fatigue gave a Lapsus$-linked attacker Uber's internal tools; Uber rotated keys to many services.
- Microsoft Midnight Blizzard breach: Midnight Blizzard (APT29) exploited legacy test account without MFA to breach Microsoft.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Password-based MFA is a risk reducer, not a trust reset: It lowers the odds of opportunistic compromise, but it still preserves the password as a weak anchor and often adds a second factor that can be phished or intercepted. That means the control reduces attacker cost without removing the attacker path. For identity programmes, the real question is whether the factor set resists modern access attacks or only satisfies a control checklist.
MFA fatigue is a governance failure, not just a user problem: Prompt bombing succeeds when organisations rely on approval-based factors and expect users to distinguish routine prompts from malicious ones under pressure. The weakness is structural because the control asks humans to arbitrate risk in the middle of an attack. Practitioners should read that as a sign that authentication design, not user awareness alone, is the issue.
Passwordless authentication is the point where phishing resistance and usability can align: When access is bound to cryptographic keys, local biometrics, and device-level checks, the factor set stops depending on a transferable secret or a user-responded prompt. That shifts identity security from interception-prone exchange to stronger device-bound assurance. For workforce identity and sensitive access, this is where the programme starts to close the gap between policy intent and actual attack resistance.
Phishable factors expose a broader identity assumption gap: Traditional MFA was designed for a world where the factor set could be trusted to remain secret or independent during the session. That assumption fails when attackers can intercept messages, reuse credentials, or manipulate approval behaviour in real time. The implication is that identity governance must distinguish between authentication that exists on paper and authentication that is actually resistant to modern compromise.
Continuous checks matter only if the initial factor is already sound: Device posture and periodic revalidation can add value, but they do not rescue a login flow built on a phishable password and a spoofable second factor. The control stack has to start with factor resistance, then layer monitoring and posture checks. That sequencing is what keeps identity assurance from collapsing under the first successful prompt abuse.
From our research library:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
- Read next: Passwordless and Passkeys Guide
What this signals
Phishable-factor debt: Password-based MFA creates a control that looks stronger than passwords alone while still depending on factors attackers can intercept or coerce. That gap keeps organisations exposed to account takeover unless they move the factor set toward device-bound, phishing-resistant authentication.
The broader programme implication is that authentication should be judged by attack resistance, not by the presence of a second step. The same logic applies across workforce identity and privileged access: if a user can be tricked, prompted, or intercepted into completing login, the control is not resilient enough.
Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password, according to the State of Secrets in AppSec.
For practitioners
- Replace phishable second factors Remove SMS, email OTP, and approval-only push flows from access paths that protect sensitive data or privileged functions.
- Prioritise passwordless for high-risk access Move sensitive workforce and privileged accounts to cryptographic, device-bound authentication where the login flow does not depend on a transferable secret.
- Harden authentication against fatigue attacks Reduce repeated prompts, investigate unusual approval bursts, and treat notification fatigue as an authentication design issue rather than a training issue.
- Review MFA coverage for privileged and remote access Check where password-based MFA still protects administrative consoles, remote access, and sensitive applications, then reclassify those paths by attack impact.
- Use device posture as a supplement, not a substitute Apply device-level security checks and continuous revalidation only after replacing weak factors, so posture signals reinforce rather than compensate for weak authentication.
Key takeaways
- Password-based MFA reduces risk but still leaves room for phishing, interception, and prompt abuse when the factors themselves are weak.
- The attack evidence shows that attackers can turn user fatigue and phishable second factors into account takeover paths.
- Phishing-resistant, passwordless authentication changes the assurance model by binding access to cryptographic keys and device context.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, OWASP ASVS and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | SP 800-63B — Authentication | The article is about authentication strength and phish resistance. |
| Recommendation — Adopt SP 800-63B-aligned authenticators that resist phishing and interception for sensitive access. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The post focuses on how authentication choices shape access assurance. |
| Recommendation — Map access paths to PR.AA-05 and remove weak factors from high-impact accounts. | ||
| OWASP ASVS | V6 — Authentication | The article discusses authentication factors, phishing resistance, and login assurance. |
| Recommendation — Use V6 to verify that authentication mechanisms are resistant to phishing and replay. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article centers on account login protections and factor choices. |
| Recommendation — Apply CIS-5 to harden account access and reduce exposure from weak MFA configurations. | ||
Key terms
- Passwordless MFA: An authentication approach that replaces passwords and code-based second factors with device-bound cryptography and local user verification. The user proves possession of a trusted device and then unlocks it with a biometric or similar control, reducing reliance on reusable secrets and delivery channels that can be intercepted.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- MFA Prompt Bombing: A social engineering attack that floods a user with repeated authentication prompts until one is approved. The control weakness is not the factor itself, but the human decision point that can be overwhelmed when the attacker already has valid credentials and can keep requesting approval.
- Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on May 29, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org