Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MFA and third-party compromise: what IAM teams are missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 19643
Topic starter  

TL;DR: A breach at a third-party telephony provider exposed DUO communication logs and user metadata after credential theft, which can fuel follow-on spear-phishing attacks, according to Unixi. The real lesson is that identity controls fail when supplier access, social engineering, and recovery pathways are not governed together.

NHIMG editorial — based on content published by Unixi: Unveiling the Limitations of MFA

Questions worth separating out

Q: What breaks when MFA is supported by insecure third-party workflows?

A: MFA breaks operationally when supplier support, telephony, or recovery workflows can be socially engineered into exposing credentials or identity data.

Q: Why do supplier breaches increase phishing risk for identity teams?

A: Supplier breaches often expose contact details, message logs, and internal context that make later phishing far more convincing.

Q: How should security teams govern third-party identity access?

A: Security teams should inventory every external identity path, assign an internal owner, and apply scope, expiry, and revocation rules to each connection.

Practitioner guidance

  • Extend MFA governance to supplier workflows Inventory every third party that can handle identity, recovery, or communications data, then classify those workflows as part of your authentication control surface.
  • Minimise identity metadata exposure Reduce the amount of names, phone numbers, and message context stored or exchanged by support and telephony systems.
  • Reassess trust in delegated recovery channels Review support and recovery processes for places where social engineering could bypass technical MFA protections.

What's in the full article

Unixi's full blog post covers the operational detail this post intentionally leaves for the source:

  • The article's own explanation of how the third-party VoIP compromise unfolded through social engineering and credential disclosure.
  • The vendor's framing of how communication logs and user metadata could be reused in later spear-phishing campaigns.
  • The specific way Unixi positions its universal SSO and phishing protections against this breach pattern.
  • The product claims around compatibility and integration that are not assessed in this editorial analysis.

👉 Read Unixi's analysis of MFA limitations and the DUO-related supplier breach →

MFA and third-party compromise: what IAM teams are missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 19234
 

Third-party credential exposure is now part of the MFA threat model: MFA programs are often designed around the primary authentication event, but this incident shows that the exploitable path may sit in a supplier workflow instead. When a telephony provider can expose communication logs and identity metadata, the security boundary extends beyond the login prompt. Practitioners should treat delegated trust as part of authentication governance, not as an adjacent risk.

A few things that frame the scale:

  • Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
  • 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, which shows how often identity governance failures go undetected until after impact.

A question worth separating out:

Q: Who is accountable when a supplier identity is abused in a breach?

A: Accountability usually spans the business owner of the service, the identity team that issued or federated access, and the third party that held the credential. Frameworks such as NIST CSF and zero-trust models expect clear ownership and revocation discipline. Without that, nobody can prove where control failed.

👉 Read our full editorial: MFA limitations exposed by third-party credential theft and social engineering



   
ReplyQuote
Share: