Join our Newsletter — 33% off our NHI Course
Home FAQ Threats, Abuse & Incident Response Why do passwords, OTPs, and push approvals still…
Threats, Abuse & Incident Response

Why do passwords, OTPs, and push approvals still leave customer accounts exposed to takeover risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Threats, Abuse & Incident Response

Passwords are vulnerable to phishing and brute force attacks, OTPs can be intercepted or extracted by phishing kits or SIM swapping, and push approvals can be worn down through prompt bombing. Each method still depends on a recoverable secret or user action that attackers can abuse, which is why they remain weaker than phishing resistant approaches.

Why These Controls Still Break Under Real Attack Pressure

Passwords, OTPs, and push approvals each add a layer, but none of them eliminate the core problem: an attacker can still win by stealing a secret, relaying a session, or manipulating the user into approving the wrong action. That is why these methods reduce casual abuse, yet still leave accounts exposed when the threat actor can operate in real time.

The failure mode is not theoretical. Passwords remain phishable and brute-forceable, OTPs can be captured through phishing kits or SIM swap abuse, and push prompts can be exhausted by repeated approval requests until the user yields. The common weakness is that the factor is still recoverable, replayable, or user-dependent.

At scale, the exposure becomes more pronounced because attack volume can be automated and targeted against the weakest recovery path. For a broader case study set on account compromise and credential abuse patterns, see The 52 NHI breaches Report and its companion analysis, 52 NHI Breaches Analysis, which show how exposed secrets, tokens, and weak access paths are repeatedly turned into takeover opportunities.

Why Attackers Prefer These Gaps

Passwords are attractive because they can be harvested at scale through phishing, credential stuffing, and password reuse. OTPs are attractive because they often arrive over channels the attacker can intercept, relay, or socially engineer, especially when the user believes the code itself proves legitimacy. Push approvals are attractive because they shift the attack from secret theft to human fatigue, where repeated prompts can wear down attention and increase the chance of a mistaken tap.

That is why these factors are not equivalent to phishing-resistant authentication. They can confirm presence or knowledge, but they do not always bind the authentication event to the specific origin, device, or transaction the user intended. Once an attacker can stand between the user and the real service, the control often protects the wrong thing.

Current guidance in identity security increasingly favours phishing-resistant methods for the highest-risk accounts because they remove the easy replay and prompt-manipulation paths that make these legacy factors fragile. Where organisations keep OTP or push as a fallback, they should treat them as degraded controls, not as a final trust boundary.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Access ControlAccess control must reduce account takeover paths and enforce stronger authentication where risk is high.
GV.RM — Risk Management StrategyThe answer hinges on residual takeover risk from weaker authentication methods.
Recommendation — Apply access-control policy to require stronger authentication for high-risk accounts and transactions. Set authentication policy based on residual account takeover risk rather than convenience alone.
CIS Controls v86 — Access Control ManagementAccount takeover risk is directly shaped by account access, authentication, and least-privilege control.
Recommendation — Restrict access paths and enforce stronger account controls for sensitive and privileged users.
NIST SP 800-63AAL — Authenticator Assurance LevelThe question concerns how assurance varies across password, OTP, and phishing-resistant authentication methods.
Recommendation — Map authentication methods to the required assurance level and prefer phishing-resistant authenticators for risky accounts.
NIST Zero Trust (SP 800-207)ID — IdentityZero Trust requires stronger identity assurance because compromised factors undermine trust decisions.
Recommendation — Require stronger identity assurance before granting access to sensitive resources.
OWASP Non-Human Identity Top 10NHI-01 — Secrets and Credential ManagementPasswords, OTP seeds, and approval channels still fail when secrets or approvals can be abused.
NHI-02 — Overprivilege and Excessive PermissionsAccount takeover impact increases when the compromised account can do too much after authentication.
Recommendation — Reduce takeover exposure by eliminating recoverable secrets and tightening credential lifecycle controls. Limit post-authentication blast radius by removing unnecessary permissions from user accounts.

Practitioner Guidance

What to verify: Check whether the factor actually resists replay, relay, and prompt fatigue in your deployment. If a login can still be completed by transferring a code or nudging a user to approve, the control is reducing risk but not closing takeover paths.

Decision rule: Use stronger phishing-resistant methods for privileged, high-value, or frequently targeted accounts, and reserve passwords, OTPs, and push approvals for lower-risk scenarios or step-up use cases where the residual takeover risk is acceptable.

What practitioners underestimate: The issue is often not a weak factor in isolation, but the combination of weak recovery, poor enrollment hygiene, and a user journey that gives attackers repeated chances to intervene before the account owner notices.

Practitioner takeaway: Treat these methods as risk-reducing controls with known bypass paths, not as proof that the account is safe from takeover.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org