The MFA You Have Isn't the MFA You Think You Have
CSO Online, Wednesday, September 30th, 2026
Explains why push and OTP-based MFA fail against targeted attackers and why phishing-resistant FIDO2 and passkeys close the gap.
Compliance reports count push notifications, SMS codes and hardware keys equally as 'MFA enabled,' masking very different levels of protection, even as push fatigue attacks and reverse-proxy phishing kits that intercept one-time codes in real time have defeated MFA in incidents such as Uber and MGM.
The shared flaw is that these methods never verify the login is going to the legitimate destination, whereas FIDO2 and passkeys bind a key pair to a specific origin, so lookalike domains fail by design.
The article urges security leaders to measure MFA by method strength rather than adoption rate.