Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do passwords and low-assurance second factors create…
Threats, Abuse & Incident Response

Why do passwords and low-assurance second factors create ongoing account takeover risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 8, 2026 Domain: Threats, Abuse & Incident Response

Passwords remain vulnerable to credential breaches, phishing, spraying, brute force attacks, and poor hygiene. Adding MFA helps, but low-assurance factors like SMS can still be bypassed or intercepted. The core problem is that attackers often only need one weak control to turn stolen or guessed credentials into account takeover.

Why Passwords and Low-Assurance Factors Keep the Door Open

Passwords are still an exposed control because they can be stolen, guessed, reused, or socially engineered, and low-assurance second factors often fail to raise the bar enough. A second factor only helps if it meaningfully resists interception, replay, and account recovery abuse. When the backup channel is weak, an attacker does not need to defeat the whole authentication stack, only the weakest link.

The practical issue is that many account takeover begin with ordinary credential compromise and end with a factor that was intended to stop exactly that path. SMS codes, for example, can be redirected through SIM swap or intercepted through session theft and phishing kits, while push fatigue and help desk recovery can bypass stronger intent than the organisation expected. For this reason, NIST SP 800-63 Digital Identity Guidelines emphasise assurance, not just the presence of a second step. In practice, many security teams discover the weakness only after a stolen password is enough to trigger a downgrade, recovery flow, or low-friction approval path.

How It Works in Practice

Account takeover risk persists because authentication is a chain, not a single control. If one segment of that chain is weak, the overall assurance drops to the level of what an attacker can bypass most easily. Passwords remain attractive to attackers because they are reusable across services, frequently phished, and often exposed in breaches. Low-assurance factors add friction, but they do not necessarily add strong resistance to active compromise.

In practice, the attacker path often looks like this:

  • Obtain a password from a breach dump, phishing page, or credential stuffing attempt.
  • Exploit a weak second factor that can be relayed, approved by mistake, or recovered through support.
  • Use the resulting session to change recovery details, enroll a new factor, or persist by adding a trusted device.

That is why the relevant question is not whether MFA exists, but whether the factor meaningfully binds the login to the legitimate user and the original device or channel. Phishing-resistant methods reduce relay and replay risk because the challenge is tied to the relying party and cannot be trivially reused elsewhere. By contrast, SMS and some one-time code flows often protect against only the most basic password-only attack, not against modern interception or social engineering. NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks shows how persistent credentials and weak lifecycle controls keep exposures alive over time; the same logic applies to human accounts when recovery and factor management remain weak.

Teams also need to treat account recovery as part of authentication, because many bypasses happen there rather than at the primary login screen. If the recovery channel is easier to abuse than the login channel, the whole assurance model collapses. This guidance tends to break down in environments that rely on legacy SMS, shared inboxes, or service desk verification steps that can be socially engineered faster than they can be audited.

Common Variations and Edge Cases

Tighter authentication usually improves security, but it can increase support load and user friction, so organisations must balance assurance against usability. The right answer is not identical for every account class.

High-risk administrative, finance, and privileged accounts deserve stronger factors and stricter recovery rules than low-impact consumer-style access. Shared devices, roaming users, and constrained field environments can make some phishing-resistant methods harder to roll out immediately, which is why current guidance suggests prioritising the most sensitive accounts first rather than waiting for perfect coverage. A temporary exception can be reasonable, but it should be time-bound, monitored, and paired with a documented migration path.

Another edge case is that “MFA enabled” does not mean “takeover resistant.” If the factor can be approved remotely without strong user intent, or if account recovery can reset the factor with weak proofing, the residual risk remains material. The same is true when applications still accept legacy fallback methods alongside modern ones. The control only becomes dependable when the weakest permitted path is removed, not when the strongest path is merely available.

Risk and Threat Considerations

The material risk is account compromise through credential replay, phishing, SIM swap, help desk abuse, or recovery-flow abuse. Low-assurance second factors can create a false sense of protection because they stop some automated attacks while leaving interactive takeover paths available.

Failure mechanism: An attacker steals or guesses a password, then exploits a weak factor or recovery channel that can be intercepted, relayed, approved under pressure, or reset through insufficient verification. The control fails when assurance is uneven across login, recovery, device enrolment, and support workflows.

Impact: The attacker can establish a valid session, change recovery details, add a new trusted device, and persist beyond the initial login. That can expose email, tokens, sensitive data, and downstream systems that trust the account.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63AAL — Authentication Assurance LevelsThe question is about weak authentication assurance and takeover resistance.
Recommendation — Require higher assurance methods where passwords and low-trust factors leave takeover risk unacceptably high.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlIt addresses authentication strength and account access protection.
Recommendation — Strengthen authentication controls so compromised credentials cannot easily become account access.
CIS Controls v86 — Access Control ManagementIt covers controlling account access and reducing weak authentication exposure.
Recommendation — Remove weak fallback access paths and enforce stronger account access controls.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementPasswords and second-factor bypasses create credential abuse patterns similar to NHI compromise.
Recommendation — Inventory and rotate exposed credentials before attackers can reuse them for takeover.
MITRE ATT&CKT1110 — Brute ForceThe question directly involves credential guessing and password attack paths.
Recommendation — Detect password-guessing activity and correlate it with takeover attempts across accounts.

Practitioner Guidance

What to prioritise: Treat the recovery path and factor enrollment path as part of the authentication boundary, not as administrative afterthoughts. If those paths are weaker than primary login, they define your real takeover exposure.

Decision rule: If a factor can be satisfied through SMS, voice, push-only approval, or help desk reset without strong binding to the user and device, classify the account as still vulnerable to takeover and raise assurance requirements for that class.

What to verify: Confirm that the weakest permitted login path has been removed for privileged and high-impact accounts, that recovery requires robust proofing, and that factor resets are logged and reviewable. A control is only trustworthy when it is testable under phishing, interception, and support-abuse scenarios.

Practitioner takeaway: The goal is not to add more steps to login, but to remove the easiest bypass path that an attacker can still use after the password is compromised.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 8, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org