Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do social engineering attacks still bypass strong…
Governance, Ownership & Risk

Why do social engineering attacks still bypass strong MFA programs?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 25, 2026 Domain: Governance, Ownership & Risk

Strong MFA can still fail if attackers can reset the factor through support channels or exhaust users with push prompts. The weakness is often not the login control itself, but the recovery path and the human workflow around it. Organisations need governance for re-enrollment, not just for sign-in.

Why This Matters for Security Teams

social engineering still defeats strong MFA because attackers rarely need to break the factor itself. They target the recovery path, the help desk, the enrolment flow, or the user’s decision-making under pressure. That is why “MFA enabled” is not the same as “identity protected.” Guidance from NIST SP 800-63 Digital Identity Guidelines and NHIMG’s Ultimate Guide to NHIs — Key Challenges and Risks both point to the same operational truth: authentication is only as strong as the surrounding identity lifecycle.

In practice, this matters because attackers use pretexting, fatigue, and support escalation to bypass controls that were designed for normal user behaviour, not adversarial behaviour. The weakness often shows up in account recovery, device replacement, or “temporary” bypass approvals that become permanent exceptions. NHIMG’s MGM Resorts Breach 2023 — Scattered Spider illustrates how real-world compromise often starts outside the login box. In practice, many security teams encounter the failure only after an attacker has already convinced support to re-enrol the factor or approve access.

How It Works in Practice

A strong MFA program can still be bypassed when it relies on static trust assumptions. If a user can be persuaded to approve a push, read out a code, install a rogue authenticator, or reset factors through a weak service desk process, the attacker has effectively moved around the control rather than through it. Current guidance suggests treating MFA as one control layer inside a broader identity assurance model, not as a stand-alone defence.

Good programs add friction where attackers exploit ambiguity. That means verifying the requester through independent channels, requiring high-assurance re-enrolment for factor resets, logging every recovery event, and limiting the number of acceptable bypass conditions. NIST’s identity guidance and CISA cyber threat advisories both reinforce that human-process controls need the same discipline as technical controls. NHIMG’s 52 NHI Breaches Analysis also shows how identity compromise often cascades once one foothold is granted.

  • Use phishing-resistant MFA where possible, especially for administrators and support staff.
  • Separate sign-in approval from recovery approval, with different evidence requirements for each.
  • Apply step-up verification for risky events such as device changes, new locations, or password resets.
  • Monitor for repeated push fatigue, unusual help desk requests, and rapid factor re-enrolment.
  • Require just-in-time approval for exceptional access and revoke it automatically when the task ends.

These controls tend to break down in outsourced service desks or high-volume customer support environments because speed targets encourage shortcuts and attackers exploit those shortcuts repeatedly.

Common Variations and Edge Cases

Tighter recovery controls often increase user friction and support load, requiring organisations to balance resilience against usability. That tradeoff is real, especially for regulated industries, executive accounts, and field workers who lose devices or work from unstable networks. Best practice is evolving, but there is no universal standard for how much recovery friction is enough.

Some environments need additional safeguards. Privileged administrators should not rely on the same factor-reset workflow as general users. Shared kiosks, contractor access, and delegated support queues often need stronger step-up checks because the attack surface is broader and the chain of custody is weaker. For higher-risk cases, combine identity proofing, device posture checks, and out-of-band verification instead of assuming a single MFA event is decisive. The broader lesson matches Ultimate Guide to NHIs — Why NHI Security Matters Now: identity controls fail when lifecycle governance is weaker than the attack path.

There is also a hard edge case with session theft. If an attacker steals a live session after MFA succeeds, the login factor may be irrelevant until the session expires or is revoked. That is why many programs now pair MFA with continuous risk evaluation, conditional access, and rapid token revocation. The practical limit is that not every application supports that level of telemetry, so teams often need compensating controls rather than a perfect model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-07Factor reset abuse often exposes weak NHI lifecycle governance.
CSA MAESTROIAM-03Identity workflows for autonomous access need stronger approval boundaries.
NIST AI RMFHuman workflow manipulation is an AI-style risk assessment problem.
NIST CSF 2.0PR.AA-05Authentication resilience depends on strong identity proofing and verification.
NIST SP 800-63AAL2MFA bypasses often arise where assurance level is undermined in recovery.

Harden recovery and re-enrolment paths, not just interactive sign-in, and log every credential change.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org