Join our Newsletter — 33% off our NHI Course

SMS MFA and phishing resistance: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

SMS MFA is an assurance gap, not just a usability compromise: The control answers a delivery problem, not a cryptographic proof problem. That distinction matters because IAM programmes often treat any second factor as equivalent when the real question is whether the factor resists phishing, interception, and recovery abuse. Practitioners should stop measuring MFA by deployment count and start measuring it by the attack paths it actually withstands.

A few things that frame the scale:

  • The IBM/Ponemon 2025 Cost of a Data Breach Report found that phishing-initiated breaches cost an average of $4.8M each.

A question worth separating out:

Q: What happens when organisations keep SMS as a fallback authentication factor?

A: Keeping SMS as a fallback preserves an easy path for attackers after they obtain a password or access to a phone number. It also encourages uneven security, where higher-risk users may still be protected by the weakest factor in the stack. Over time, that undermines zero trust assumptions and leaves critical accounts exposed to bypass attacks.

👉 Read our full editorial: SMS MFA is a weak control for high-assurance identity


This topic was modified 5 hours ago 2 times by NHI Mgmt Group

   
Quote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.