Skip to content
Cyber Defense Technologies

Insights

Phishing-Resistant MFA: Why Some Second Factors Are Better Than Others

Multifactor authentication stops most password attacks, but attackers have learned to steal one-time codes and abuse push notifications. What makes MFA phishing-resistant, what federal policy requires, and how to roll it out without disrupting the mission.

By Cyber Defense Technologies October 2, 2026 5 min read

Multifactor authentication (MFA) is one of the most effective security controls an organization can deploy. A stolen password alone is no longer enough to sign in. That effectiveness is exactly why attackers have spent the last several years learning to get around it.

The answer is not to abandon MFA, but to use forms of it that attackers cannot easily phish.

How attackers get around ordinary MFA

Real-time phishing (adversary-in-the-middle). The victim receives a convincing link to a fake sign-in page. The fake page passes everything the victim types, including the one-time code, straight to the real website and captures the resulting session. Phishing kits that automate this are widely available.

MFA fatigue (push bombing). An attacker who already has a password triggers sign-in requests repeatedly, sending push notifications to the victim's phone until the victim approves one to make them stop, or approves one by mistake.

SIM swapping. Criminals persuade or bribe a mobile carrier to move a victim's phone number to a new SIM card, then receive text-message codes themselves.

Social engineering the help desk. An attacker calls the help desk posing as an employee who has lost their phone and asks for MFA to be reset.

These techniques have been used in widely reported intrusions against large, well-resourced organizations. None of them requires breaking cryptography. They exploit the fact that a code or an approval can be passed along by a person who has been fooled.

Second factors, strongest first

  1. Phishing-resistant

    FIDO2 security keys, passkeys, and PIV or CAC smart cards bind each sign-in to the real site.

  2. Push with number matching

    The user types a number from the sign-in screen, which blunts push fatigue but can still be phished.

  3. Authenticator app codes

    Better than SMS, but codes can be relayed by a fake sign-in page in real time.

  4. Text and voice codes

    Better than a password alone, but exposed to SIM swapping and real-time phishing.

  5. Password only

    One stolen or reused password is enough for an attacker.

What makes MFA phishing-resistant

Phishing-resistant authenticators use public-key cryptography and bind each sign-in to the legitimate website or service. When you register a security key or passkey with a website, the authenticator creates a key pair specifically for that site. At sign-in, the authenticator checks which site is asking and only responds to the real one. A look-alike domain receives nothing it can replay, no matter how convincing it looks or how careful the user is.

The main options are:

  • FIDO2 / WebAuthn security keys. Small hardware keys that plug in over USB or tap over NFC.
  • Passkeys. FIDO credentials stored on a phone, computer or password manager and unlocked with a fingerprint, face or PIN.
  • PIV and CAC smart cards. The federal and DoD standard, using certificates on a card with a PIN.
  • Platform authenticators. Credentials built into managed devices, such as those backed by a computer's trusted platform module.

NIST's digital identity guidelines, SP 800-63B, describe resistance to verifier impersonation (phishing) as a requirement at the highest authenticator assurance level.

What federal policy requires

In January 2022, the Office of Management and Budget issued memorandum M-22-09, the federal zero trust strategy. It directs agencies to use phishing-resistant MFA for agency staff, contractors and partners, and to offer it to the public as an option. CISA has published fact sheets on implementing phishing-resistant MFA and on number matching as an interim step for organizations still relying on push notifications.

For the Department of War, PIV and CAC authentication has long been the norm on DoD networks. The same principle increasingly applies to cloud services, administrative interfaces and the systems contractors use to handle sensitive information.

A practical rollout

Phishing-resistant MFA is mature and widely supported, but rolling it out across an organization takes planning.

  1. Start with the highest-value accounts. Administrators, privileged and service-management accounts, remote access, email and cloud consoles.
  2. Inventory applications. Identify which systems support FIDO2, smart cards or federation through a central identity provider, and which need upgrades or a different approach.
  3. Plan enrollment. Issue keys or enable passkeys in person or through a verified process, so attackers cannot enroll their own authenticators.
  4. Plan for loss and recovery. Give people a backup authenticator and design a recovery process that resists social engineering. The help desk is often the weakest point.
  5. Handle exceptions deliberately. Some legacy systems cannot support modern authentication. Document them, compensate with network restrictions and monitoring, and set dates for retirement.
  6. Retire weaker methods. Once phishing-resistant options are in place, remove fallback to text codes and push for the protected accounts. Attackers will always choose the weakest option still allowed.

Interim improvements

If phishing-resistant MFA is not yet possible everywhere, some improvements reduce risk quickly:

  • Turn on number matching for push notifications, so users must type a number shown on the sign-in screen.
  • Limit the number and rate of push requests, and alert on repeated denials.
  • Use conditional access to require managed devices for sensitive applications.
  • Tighten help desk identity verification for MFA resets.

Frequently asked questions

Are passkeys as strong as hardware security keys? Both are phishing-resistant. Hardware keys keep the credential on a dedicated device, which some high-security environments prefer. Synced passkeys are more convenient and still bind sign-ins to the real website.

Does phishing-resistant MFA stop all account takeover? No. Attackers can still steal session cookies from compromised devices or abuse overly broad permissions. MFA must be combined with device security, session controls and monitoring.

What about service accounts that cannot use MFA? Restrict where they can sign in from, rotate their credentials, monitor their use closely and replace them with managed identities where possible.

How CDT can help

CDT helps organizations design and test strong identity controls. Our secure architecture engineers plan phishing-resistant authentication that fits mission systems and classified environments, our penetration testing and social engineering teams test whether MFA and help desk processes hold up against realistic attacks, and our hardening work removes the weaker fallbacks attackers rely on.

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.