Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› What breaks when organisations rely on one-time codes…
Authentication, Authorisation & Trust

What breaks when organisations rely on one-time codes alone for protecting high-value user accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Authentication, Authorisation & Trust

One-time codes improve access control, but they still leave gaps against phishing, malware, and man-in-the-middle attacks. If an attacker captures the code in real time, the protection collapses. SMS delivery also depends on mobile carriers and phone access, which introduces recovery and interception risks. For sensitive accounts, code-based MFA is a weaker control than hardware-backed authentication.

Why one-time codes stop being enough on high-value accounts

One-time codes improve access control, but they still leave gaps against phishing, malware, and man-in-the-middle attacks. If an attacker captures the code in real time, the protection collapses. SMS delivery also depends on mobile carriers and phone access, which introduces recovery and interception risks. For sensitive accounts, code-based MFA is a weaker control than hardware-backed authentication.

The core problem is that a one-time code usually proves possession at a single moment, not a durable, phishing-resistant binding between the user, the device, and the login session. That means it can be replayed quickly enough to satisfy an attacker-controlled sign-in flow, especially when the victim is tricked into entering the code into a fake site or proxy.

SMS codes are especially fragile because they rely on telecom delivery and a reachable phone number. If the number is swapped, forwarded, intercepted, or simply unavailable, the account recovery path becomes part of the attack surface rather than a safety net. High-value accounts need authentication that resists interception and is tied to the legitimate origin of the sign-in request.

What attack paths remain open when codes are the only second factor?

Phishing kits and real-time proxy attacks are the most obvious failure mode, because they can harvest a valid code and immediately use it before it expires. Malware on the endpoint can also capture a code from the browser, notification stream, or SMS inbox. In practice, the control is only as strong as the attacker’s ability to observe or relay that short-lived secret.

For this reason, organisations that want stronger MFA should treat hardware-backed methods, passkeys, or other phishing-resistant authenticators as the benchmark for high-value accounts. Guidance on phishing-resistant MFA shows why relay, fatigue, and token theft defeat weaker factors, while Twilio 0ktapus breach 2022 illustrates how SMS phishing can be operationalised at scale.

Account takeover risk also increases when one-time codes are used as the last barrier for privileged or externally reachable systems. A stolen code can unlock not just a mailbox or portal, but password reset flows, recovery options, and downstream authorisations that were never meant to be exposed to a transient attacker.

What stronger authentication changes for sensitive user accounts?

Stronger authentication changes the failure model from “can the attacker read a code in time?” to “can the attacker satisfy a cryptographic challenge bound to the legitimate device and origin?” That materially raises the cost of phishing and interception. It also reduces dependence on brittle recovery channels, which matters when account access itself protects payments, admin tools, customer data, or corporate control planes.

For sensitive accounts, the right comparison is not OTP versus no OTP, but OTP versus phishing-resistant methods that make real-time relaying ineffective. The MFA Guide is useful here because it separates SMS, authenticator-app codes, and security keys by how well they resist interception, and it helps teams see why “MFA enabled” is not the same as “MFA fit for purpose.”

Where organisations support break-glass access, the recovery path must be designed separately from everyday user sign-in. The Break-Glass and Emergency Access Account Guide is relevant because emergency access often becomes the fallback after a lost phone, MFA outage, or lockout, and that fallback needs tighter monitoring than ordinary login flows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5, OWASP ASVS and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationOne-time codes can be intercepted or relayed in real time.
NHI-07 — Long-Lived SecretsSMS and reusable recovery paths increase exposure when code delivery is compromised.
NHI-10 — Human Use of NHIHuman handling of codes and recovery steps creates interception risk.
Recommendation — Require phishing-resistant authentication for high-value accounts. Minimise reliance on reusable recovery factors and rotate exposed credentials quickly. Reduce human-mediated secret handling in authentication flows.
NIST SP 800-63Digital Identity GuidelinesThe topic is authentication assurance and phishing resistance for user accounts.
Recommendation — Use phishing-resistant authenticators at higher assurance levels for sensitive accounts.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)High-value user accounts need stronger sign-in controls than codes alone.
IA-5 — Authenticator ManagementCode-based MFA depends on secure issuance, delivery, and lifecycle control.
IA-9 — Identification and Authentication (Non-Organizational Users)The account-risk pattern also applies when external user accounts are high value.
Recommendation — Enforce stronger authenticators for organizational user access. Manage authenticators with tight issuance, rotation, and revocation. Apply stronger authentication controls to externally managed accounts.
OWASP ASVSV6 — AuthenticationThe question concerns whether OTP-only authentication is sufficient.
V10 — OAuth and OIDCHigh-value account access often depends on federation and sign-in assurance.
Recommendation — Verify phishing-resistant authentication requirements for sensitive user flows. Validate federated sign-in assurance and resistance to token relay.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication and Access ControlThe issue is whether the access control strength matches the account value.
Recommendation — Strengthen authentication controls where account impact is high.

Practitioner Guidance

What to verify: If an account can trigger privileged actions, recovery workflows, financial actions, or admin changes, verify that a phishing-resistant factor is available and actually enforced for that population. Do not assume that an SMS or app code meets the bar simply because it is technically “multi-factor.”

Decision rule: If the account is high-value, internet-exposed, or used to administer other systems, move away from one-time codes as the primary control and require a hardware-backed or equivalent phishing-resistant method. Keep code-based MFA only where the blast radius is modest and the residual risk is acceptable.

What practitioners underestimate: The weak point is often not the login prompt itself, but the recovery chain around it, including phone access, carrier dependency, and support-led resets. Those paths deserve the same scrutiny as the initial authentication method.

Practitioner takeaway: One-time codes are useful as a convenience layer, but high-value accounts need authentication that survives real-time phishing and session relay, not just a second box to type into.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org