One-time code MFA increases risk because it can be bypassed by phishing kits, token theft, and adversary-in-the-middle attacks. It creates a false sense of protection when attackers can intercept or replay the second factor. In practice, weak MFA may reduce friction for users while leaving account takeover paths open, especially when authentication is not tied to device trust or contextual checks.
Why one-time code MFA still leaves account takeover paths open
One-time codes are better than passwords alone, but they are still a shared-secret style factor that can be captured and replayed in real time. Because the code is short-lived and human-entered, it is vulnerable to phishing proxies, help-desk social engineering, malware, and session token theft. That means the second factor often confirms user presence without strongly proving device or context.
Where OTP-based MFA breaks under modern phishing
The core weakness is not the code itself, it is the trust model around it. Attackers use kits that relay the login flow to the real site, capture the OTP, and complete the session before the code expires. The same pattern shows up in campaigns that combine credential theft with adversary-in-the-middle interception, where the attacker takes over the authenticated session rather than “breaking” the code.
One-time code MFA also struggles when an attacker can coerce a user into approving or divulging the factor under pressure. Once the code is entered into a fake login page, the attacker can immediately exchange it for a valid session and often avoid further challenges. If the organisation treats the code as sufficient proof of trust, downstream controls may never get a chance to intervene.
What stronger authentication changes in practice
Phishing-resistant MFA changes the attack economics by binding authentication to a trusted origin, device, or cryptographic key rather than a reusable code. NIST SP 800-63 Digital Identity Guidelines is the clearest external reference for this shift, especially where authenticator assurance and phishing resistance matter more than a second prompt.
That is why passkeys, security keys, and device-bound authenticators are materially better for high-value accounts. They make interception and replay much harder, and they reduce the value of a fake login page because the authenticator responds only to the legitimate origin. In environments with sensitive data or privileged access, the question is not whether MFA exists, but whether it resists real-time phishing and token theft.
In identity operations, the broader control problem is lifecycle and recovery, not just sign-in. The Workforce Identity Security Guide and Passwordless and Passkeys Guide both reflect the same operational point: if help-desk resets, recovery paths, or fallback factors are weak, attackers simply bypass the “strong” factor through the weakest adjacent process.
Risk and Threat Considerations
One-time code MFA creates a false sense of closure because the visible control is stronger than the actual trust boundary. Attackers target the login flow, not the factor, so the main exposure is real-time phishing, session hijacking, and recovery-path abuse that can turn a valid OTP into full account control.
Failure mechanism: The attacker captures credentials and the OTP through a phishing proxy or social engineering flow, then immediately uses the code to establish a legitimate session or steal the resulting session token.
Impact: The account can be taken over without defeating MFA in the traditional sense, which means privileged access, email access, SaaS access, and downstream internal tools may all be exposed even though MFA was “enabled.”
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST SP 800-53 Rev 5, NIST Zero Trust (SP 800-207) and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Directly addresses phishing-resistant authenticators and assurance levels for sign-in. |
| Recommendation — Adopt phishing-resistant authenticators for high-value accounts and phase out OTP as the primary control. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Covers lifecycle and handling of authenticators, including issuance, rotation and revocation. |
| IA-2 — Identification and Authentication (Organizational Users) | Applies because workforce accounts need stronger authentication than reusable one-time codes for sensitive access. | |
| Recommendation — Manage authenticators with strict issuance, rotation, revocation and recovery controls. Require stronger user authentication for sensitive workforce access and privileged systems. | ||
| NIST Zero Trust (SP 800-207) | Zero Trust Architecture | Supports continuous verification and reduced trust in any single authentication event. |
| Recommendation — Bind access decisions to continuous verification and contextual trust signals, not one login event. | ||
| CIS Controls v8 | 5 — Account Management | Account and authenticator governance are central when weak MFA creates takeover exposure. |
| Recommendation — Inventory, review and promptly revoke accounts and access paths that can bypass stronger authentication. | ||
Practitioner Guidance
What to prioritise: Treat phishing resistance as the decision criterion for high-value identities, not whether a second factor is present. If the account can reach email, finance, admin consoles, developer tools, or sensitive customer data, a one-time code should be treated as a transitional control rather than the end state.
What to verify: Check whether recovery, reset, and fallback paths are equally strong. A common failure mode is deploying better MFA while leaving password reset, help-desk verification, or session renewal weak enough for an attacker to walk around the control.
Practitioner takeaway: The real question is whether the second factor still protects you when the user is being actively phished in real time; if it does not bind authentication to origin, device, or cryptographic possession, it may reduce friction more than it reduces breach risk.
Related resources from NHI Mgmt Group
- Why do identity-heavy environments increase breach risk when organisations rely only on MFA or SSO?
- Why do SMS and push-based one-time passwords increase risk during phishing campaigns against identity providers?
- Why does relying on SMS one-time passwords increase payment risk in PSD2 environments?
- What is the difference between passwordless MFA and one-time code MFA?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org