Fixed MFA fails because it verifies a step, not the quality of the identity signal behind it. Attackers can intercept, replay, or proxy OTP-based flows, then pair them with convincing synthetic behaviour that makes the login look legitimate unless the system evaluates context and session trust as well.
Why fixed MFA breaks down against modern identity attacks
Fixed MFA methods are designed to prove that a user completed a challenge, but that alone does not prove the login is genuine. If an attacker can capture or relay the second factor, or drive the victim through a convincing proxy flow, the control can be satisfied while the underlying identity signal remains untrustworthy.
That is why the weakness is not simply “MFA was bypassed.” The deeper problem is that static factors are often evaluated as a one-time checkpoint rather than as part of an ongoing trust decision. Once a session is established, a lookalike interaction can be good enough for the control but still wrong for the risk.
Fixed methods also age poorly because they stay constant while attacker tradecraft changes. OTPs, push approvals, and SMS codes remain vulnerable to interception, relay, fatigue, and social engineering, especially when the attack combines automation with human-like pacing and context. In practice, the method may still be valid even when the actor behind it is not.
Why context and session trust matter more than the code itself
The main security failure is treating MFA as a static event instead of a signal inside a broader identity decision. A code, prompt, or approval does not say much on its own if the system cannot assess whether the device, network, session continuity, user behaviour, and recovery path all fit the expected profile. Stronger controls look beyond the factor and evaluate whether the whole interaction remains coherent.
This is where phishing-resistant methods and session-aware controls outperform legacy MFA. Methods such as passkeys, device-bound authenticators, and modern federation reduce the number of places an attacker can intercept or replay a step. Just as important, they make it harder for a proxy or adversary-in-the-middle flow to present itself as a normal sign-in while quietly diverting the trust signal.
For practitioners, the key distinction is between MFA method selection and the trust model around it. If the organisation still accepts only a completed challenge as proof, the attacker can focus on making the challenge look routine rather than breaking the authentication protocol itself.
What AI-driven identity attacks change for defenders
AI-assisted attacks raise the quality and scale of deception. Attackers can generate convincing prompts, adapt in real time to user responses, and vary timing, wording, or follow-up steps so the interaction feels legitimate. That makes brittle MFA especially weak because it cannot tell whether the person approving the challenge is the real user, a coerced user, or an automated proxy in the middle.
The defensive implication is that identity security now has to include behavioural and session-level corroboration. Signals such as impossible travel, abnormal device posture, token replay patterns, unusual enrolment changes, and recovery-path abuse become more important than the mere presence of a valid OTP or push approval. If those signals are not part of the decision, AI can improve the attacker’s mimicry faster than fixed MFA can improve its own checks.
Attack patterns documented in SMS phishing and OTP relay campaigns show how easily a one-time code can be turned into a reusable access path when the attacker controls the user flow. The same lesson appears in session-token theft incidents, where the attacker no longer needs to win the second factor if a valid session can be stolen or replayed.
Risk and Threat Considerations
Fixed MFA creates a false sense of assurance when the control is evaluated at the wrong layer. The risk is account takeover through relay, token theft, push fatigue, recovery abuse, or session hijacking, followed by lateral movement from what appeared to be a legitimate login.
Failure mechanism: The attacker defeats the factor presentation rather than the identity itself, then preserves access by reusing the authenticated session or by operating inside a trusted-looking workflow.
Impact: Defenders may see a successful MFA event and miss the compromise, which increases dwell time, weakens alerting, and allows high-value actions to proceed under a valid session.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authenticators and assurance levels directly address MFA strength and identity proofing. |
| Recommendation — Adopt phishing-resistant authenticators and verify assurance levels for higher-risk access. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Organizational login controls must distinguish real authentication from replayed or proxied MFA. |
| IA-5 — Authenticator Management | MFA failures often stem from weak authenticator lifecycle, interception, or replay exposure. | |
| IA-9 — Service Identification and Authentication | Session- and token-related identity attacks often depend on machine and service authentication paths. | |
| Recommendation — Require stronger organizational user authentication for sensitive access paths. Manage authenticators to reduce interception, replay, and recovery abuse. Authenticate services and sessions with controls that resist replay and token theft. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Context-aware trust and continuous verification are central to resisting AI-driven identity attacks. |
| Recommendation — Continuously verify identity, device, and session trust instead of trusting one completed step. | ||
| OWASP ASVS | V6 — Authentication | Authentication verification must resist phishing, replay, and other MFA bypass paths. |
| V7 — Session Management | Session trust is part of the answer because attackers often bypass MFA by stealing or replaying sessions. | |
| V10 — OAuth and OIDC | Federated login and token handling are common places where fixed MFA assumptions fail. | |
| Recommendation — Verify authentication flows for phishing resistance and replay resistance. Harden session handling so a valid session cannot outlive trust in the actor. Review federation and token flows for replay, interception, and step-up gaps. | ||
Practitioner Guidance
What to prioritise: Treat phishing-resistant MFA and session controls as a package, not as separate purchases. If the control cannot resist relay, token theft, or approval abuse, it should not be the final barrier for privileged or high-risk access.
What to verify: Confirm that sign-in decisions use context such as device state, session age, anomalous enrolment, and recovery-path changes. A login that completes MFA but arrives from an implausible context should not be treated as a routine success.
Practitioner takeaway: Fixed MFA fails when the organisation confuses “challenge completed” with “identity proven”; the practical goal is to make authentication resistant to proxying, and to bind access to an ongoing trust signal rather than a single step.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org