Legacy MFA creates risk because it still depends on a person reacting to a prompt, code, or notification. Generative AI makes phishing, deepfake calls, and tailored social engineering far more convincing, so attackers can more easily trick users into approving access or sharing codes. Once the human is manipulated, the control no longer protects the account in practice.
Why This Matters for Security Teams
Legacy MFA was built for a world where the attacker had to defeat a static factor, not a live person. Generative AI changes the economics of abuse by making pretexting faster, more believable, and easier to personalise at scale. That matters because the control failure is no longer technical only, it becomes behavioural: a user can be guided into approving a push, reading out a code, or handing over a one-time secret. Once that interaction is manipulated, the MFA step can be converted from a barrier into an enabler.
This is why modern attacks increasingly focus on the user journey around authentication, not just the credential itself. Voice cloning, synthetic urgency, and highly targeted messages reduce the warning signals people used to rely on. In practice, many security teams discover the weakness only after an approval is granted or a code is shared, rather than through a clean authentication failure.
How It Works in Practice
Legacy MFA methods are strongest when they are paired with a verification step that resists real-time social engineering. They are weakest when they assume the human will recognise deception under pressure. Generative AI improves both the scale and the quality of the attack by letting adversaries create messages, calls, and follow-up prompts that sound consistent, contextual, and urgent.
The main failure paths are straightforward:
- Push fatigue, where repeated prompts train the user to approve quickly.
- Code interception, where the attacker impersonates support, IT, or a trusted contact and asks the user to read back the code.
- Session theft after authentication, where the attacker uses the user’s approval to capture a live session rather than the password.
- Deepfake-assisted social engineering, where voice or video reduces the chance that the target pauses to verify the request.
The important distinction is that the MFA factor is still functioning as designed, but the design assumes the user can distinguish legitimate from fraudulent requests. Generative AI attacks that assumption directly, which is why the risk rises even when the authentication product itself has not changed. A control that depends on user recognition of a single event is fragile when the attacker can continuously adapt the story around that event.
That is also why security teams should not treat all MFA as equally resistant. Methods that rely on shared secrets or simple approval gestures are much easier to coerce than methods that bind the challenge to a specific device, origin, or transaction context. These controls tend to break down when users are allowed to approve authentication requests under time pressure without a second trust signal.
Common Variations and Edge Cases
Tighter authentication often increases user friction, so organisations have to balance convenience against the ability to resist real-time persuasion. The common mistake is to treat every MFA prompt as equally trustworthy and every successful approval as evidence of user intent.
Some environments are harder to harden than others. Help desks, contractors, executives, and remote staff are disproportionately exposed because they are easier to impersonate and are often accustomed to exceptions. Legacy methods also vary in weakness: SMS codes are vulnerable to interception and social engineering, while app prompts can be vulnerable to fatigue unless they include number matching or similar verification. Current guidance suggests treating voice and text as weak assurance channels when an attacker may be using synthetic media.
NIST AI 600-1 GenAI Profile is useful here because it frames generative AI as a risk amplifier that changes how organisations should think about provenance, trust, and user deception.
Risk and Threat Considerations
The material risk is not only account takeover, but also the erosion of trust in human-operated verification steps. Generative AI lets attackers imitate internal language, escalate urgency, and mimic familiar voices or workflows, which increases the chance that a legitimate user will complete the challenge on the attacker’s behalf.
Failure mechanism: The attacker uses AI-generated phishing, voice cloning, or conversation chaining to move the target from suspicion to compliance. The MFA method succeeds technically, but the human is manipulated into approving the request, relaying the code, or authorising a session that the attacker controls.
Impact: The immediate consequence is account compromise, but the larger risk is blast radius. Once an attacker has a valid session or trusted approval, they can often pivot into email, SaaS, admin consoles, and downstream systems without triggering the same defences that blocked password attacks.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and MITRE ATT&CK address the attack surface, NIST AI 600-1 and CIS Controls v8 set the technical controls, and ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST AI 600-1 | GenAI Profile — Generative AI Risk Profile | Generative AI changes the deception and trust model behind MFA attacks. |
| Recommendation — Apply GenAI profile guidance to reduce user-deception and provenance risk in authentication flows. | ||
| ISO/IEC 42001:2023 | AIMS — AI Management System | AI-driven phishing and deepfake abuse requires governance over AI-related risk. |
| Recommendation — Establish AI governance controls that address deception, misuse, and trust failure in security workflows. | ||
| OWASP Agentic AI Top 10 | A1 — Agentic Access Control | AI-assisted impersonation can exploit user-mediated approvals and access decisions. |
| Recommendation — Limit human-mediated approvals and bind access decisions to stronger verification signals. | ||
| CIS Controls v8 | 6 — Access Control Management | Stronger access control reduces exposure when MFA is coerced or bypassed socially. |
| Recommendation — Harden access paths and remove weak authentication methods for sensitive systems. | ||
| MITRE ATT&CK | T1566 — Phishing | GenAI increases phishing realism and scale against authentication users. |
| Recommendation — Detect and train against AI-enhanced phishing and related social engineering attempts. | ||
Practitioner Guidance
What to prioritise: Treat any MFA method that depends on the user recognising a prompt as a higher-risk control in a GenAI threat environment. Prioritise moving critical access paths to phishing-resistant methods, especially for privileged, finance, support, and remote-admin workflows.
What to verify: Confirm whether the organisation can still distinguish a genuine login from a coerced approval in a real incident. If the answer depends on user memory, tone, or caller recognition, the assurance model is too weak for high-value accounts.
Decision rule: If an attacker can plausibly contact the user in real time, assume prompt-based MFA can be socially engineered and require a stronger control for that workflow. If the workflow cannot tolerate that risk, remove the human decision from the trust path.
Practitioner takeaway: The core issue is not that MFA stopped working, it is that GenAI makes the human checkpoint easier to exploit than many teams realise, so assurance must shift from user reaction to context-bound verification.
Related resources from NHI Mgmt Group
- Why does generative AI create risk when attackers use it to produce deceptive content for recruitment, threats, or exploitation?
- How should organisations reduce business email compromise risk when attackers use generative AI?
- Why do flat networks create more risk when attackers use AI?
- How should security teams reduce impersonation risk when attackers use generative AI to mimic trusted senders?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 16, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org