TL;DR: Traditional MFA and 2FA are increasingly bypassed by phishing, credential stuffing, push bombing, and man-in-the-middle attacks, prompting CISA, NIST, and the White House to push phishing-resistant MFA, according to Axiad. The core issue is that many programmes still treat MFA as sufficient when the real control gap is whether the factor can withstand modern adversary tooling.
Editorial analysis by NHI Mgmt Group, based on content published by Axiad: “Is Your MFA Broken?”.
Key questions
A: Adoption slows when issuance, replacement, recovery, and revocation are handled manually.
Q: Why do phishing-resistant MFA methods matter if attackers can still get in?
A: They materially reduce real-time credential harvesting and replay attacks, which removes one of the easiest entry paths.
Q: What is the difference between PKI and FIDO for authentication?
A: PKI is better suited to certificate-backed, device-centric, and non-browser use cases such as workstations and servers.
Practitioner guidance
- Define phishing-resistant MFA by use case Separate browser sign-in, workstation access, server access, and non-browser authentication so each flow gets the method that can actually resist phishing and replay.
- Phase out proxyable factor methods Retire SMS, email OTP, and push-approval flows where they can be coerced, intercepted, or approved without origin binding.
- Prioritise PKI for non-browser access Use certificate-based authentication where workloads, devices, or privileged non-browser sessions need cryptographic proof tied to the authentic endpoint.
Bottom line: Traditional MFA can satisfy a policy requirement while still failing against modern phishing and proxy attacks.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phishing-resistant MFA is an assurance control, not a quantity control: The article is correct to shift the conversation away from how many factors are present and toward whether the factor can be replayed, proxied, or socially engineered. That matters because the operational risk lives in the authentication ceremony, not the label attached to it. Practitioners should treat weak MFA as a false sense of security problem, not a partially implemented control.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: When should organisations replace legacy MFA with phishing-resistant MFA?
A: They should do it first for privileged accounts, remote access, and any workflow that attackers can target with phishing or adversary-in-the-middle attacks. If the access path protects sensitive systems and the current factor can be replayed or approved out of band, the upgrade should move from backlog to priority.
👉 Read our full editorial: Phishing-resistant MFA is now the baseline for identity security