How Attackers Are Circumventing MFA (And How To Stop Them)
Security Boulevard, Tuesday, August 15,2023
Zero Trust security models call for the use of multi-factor authentication (MFA) to ensure that only authorized users may access protected IT resources. Many organizations are adopting MFA to add a layer of security for remote workers. Customer-facing organizations are also implementing MFA to mitigate identity-based attacks, such as phishing, and to help quash the rise in account takeover fraud.
For five consecutive years, the leading cause of breaches has been compromised credentials - in other words, the use of stolen passwords. MFA renders the use of stolen credentials futile, as attackers are highly unlikely to have access to a user's other authentication factors, such as a mobile phone.
Microsoft has stated that using MFA may stop 99% of password-related attacks within an enterprise, so an increasing number of enterprises have begun to require MFA before granting account access. That's the good news. The bad news is that attackers are now trying to undermine the effectiveness of MFA with some success.