Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do password and SMS-based factors leave organisations…
Threats, Abuse & Incident Response

Why do password and SMS-based factors leave organisations exposed even when multi-factor authentication is enabled?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 26, 2026 Domain: Threats, Abuse & Incident Response

Password and SMS combinations still depend on secrets that can be stolen, intercepted, or redirected. If an attacker controls a mailbox, phone number, or session, they can capture second-factor codes and bypass the intended control. Security teams should treat those methods as stronger than passwords alone, but not as sufficient protection for sensitive or privileged access.

Why This Matters for Security Teams

Password and SMS-based factors reduce risk compared with passwords alone, but they still anchor authentication to secrets and channels that are routinely targeted. A password can be phished, reused, or recovered from a breach, while SMS codes can be intercepted through SIM swap, call forwarding abuse, malware, or compromised device access. That means the control can be bypassed without breaking cryptography or defeating policy.

This matters most when the protected asset is a privileged dashboard, admin console, mailbox, or identity provider session. In those cases, the attacker does not need every account on the network. They only need the one factor path that is easiest to redirect. NIST guidance on authentication controls in NIST SP 800-53 Rev 5 Security and Privacy Controls makes clear that stronger assurance depends on the authenticator type, not just the presence of a second step.

NHI Management Group research shows why this still matters in real environments: Ultimate Guide to NHIs — Why NHI Security Matters Now reports that 79% of organisations have experienced secrets leaks, and 77% of those incidents caused tangible damage. In practice, many security teams discover the weakness only after a mailbox takeover, SIM swap, or session hijack has already turned “MFA-enabled” into “still exploitable.”

How It Works in Practice

The practical issue is that SMS and password combinations authenticate possession of a recoverable secret or a redirectable channel, not the strength of the user session itself. If an attacker can reset the password, enroll a new device, or take control of the phone number, the second factor becomes another step in the attack path rather than a barrier. That is why current guidance increasingly prefers phishing-resistant authenticators for sensitive access, and why ISO/IEC 27001:2022 Information Security Management implementations often pair MFA with device trust, conditional access, and session monitoring.

For organisations, the implementation pattern usually looks like this:

  • Use SMS only for low-risk recovery or low-impact workflows, not privileged access.
  • Prefer phishing-resistant methods where the factor is bound to the origin or device, not just the phone number.
  • Require step-up controls for admin actions, high-value data, and session re-authentication.
  • Reduce reliance on shared recovery paths such as email reset links and help-desk overrides.
  • Monitor for identity events that indicate takeover, including SIM change, mailbox forwarding rules, and anomalous session replay.

NHIMG research reinforces the operational reality: the 52 NHI Breaches Analysis shows how credential abuse often succeeds through weak lifecycle controls and over-trusted identity paths, not through one dramatic exploit. The lesson for human authentication is similar. When the second factor is delivered through a channel an attacker can intercept or redirect, the organisation is relying on reachability rather than assurance.

These controls tend to break down in environments with weak telecom governance, unmanaged BYOD devices, and broad help-desk reset authority because attackers can pivot from recovery to full session takeover without triggering a clear challenge failure.

Common Variations and Edge Cases

Tighter authentication often increases user friction and support overhead, requiring organisations to balance stronger assurance against account recovery complexity and adoption risk. That tradeoff is why some teams keep SMS in place for legacy users or low-risk populations while reserving stronger methods for admins and finance systems.

There is no universal standard for this yet, but best practice is evolving toward risk-based and phishing-resistant authentication. For high-value access, current guidance suggests treating SMS as a transitional control rather than a destination state. Passwordless or hardware-backed methods usually outperform password plus SMS because they reduce secret replay and channel hijack risk. However, they still need lifecycle discipline, device recovery planning, and session revocation when a phone, token, or enrollment path is lost.

One edge case is emergency access. Break-glass accounts may still require fallback methods, but those paths should be tightly monitored, heavily logged, and isolated from normal operations. Another is consumer-facing services, where SMS can remain acceptable for convenience if the impact of compromise is low and the organisation has strong fraud detection. For sensitive internal systems, though, password plus SMS often gives a false sense of safety. The control is present, but the assurance is weaker than teams assume.

For security leaders, the question is not whether MFA exists, but whether the factor can resist phishing, interception, and recovery abuse in the real attack path.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-1Authentication assurance must match the risk of the protected session.
NIST SP 800-63AAL2SMS and passwords often fail to meet stronger authenticator assurance needs.
OWASP Non-Human Identity Top 10NHI-01Secret-based access patterns mirror the same weakness seen in NHI compromise.
CSA MAESTROIAM-03Agent and identity governance both require stronger control over credential replay.
NIST AI RMFRisk governance should account for identity compromise pathways and recovery abuse.

Assume any reusable secret path can be intercepted and rotate toward stronger trust signals.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org