← Back to Insights

Phishing-Resistant MFA: Why SMS Codes and Push Prompts Are No Longer Enough

MFA

Read the complete guide: How do you make your IT cyber-insurance defensible? A 2026 guide for commercial businesses.

Most professional services firms turned on multifactor authentication years ago, checked the box, and moved on. That instinct was right. The problem is that the box has quietly split in two. The MFA that carriers, regulators, and attackers all cared about in 2021 is not the MFA that stops a determined intruder in 2026. Text-message codes and one-tap approval prompts, the two most common methods small firms deployed, are now the two attackers defeat most reliably. Understanding why, and what replaces them, is the difference between MFA that looks protective on paper and MFA that actually holds.

The two attacks that broke ordinary MFA

When a login asks for a code or a tap, a human is in the loop. Attackers learned to exploit that human, and they built two repeatable techniques to do it.

The first is MFA fatigue, also called push bombing. An attacker who already has a working password sends a flood of approval prompts to the user's phone, often late at night, until the user taps "approve" just to make the notifications stop. It is not sophisticated. It works because it targets annoyance, not technology. CISA has documented push bombing as a primary technique in real intrusions and now explicitly recommends moving off simple push approval for that reason.

The second is the adversary-in-the-middle attack, and it is the one that should worry every firm still typing codes. The attacker sends a convincing email that links to a proxy site sitting invisibly between the user and the real login page. The user enters the password and the six-digit code on what looks like the genuine sign-in screen. The proxy relays both to the real service in real time, captures the resulting session token, and walks straight in. The victim's second factor worked perfectly and protected nothing, because the code was valid and the attacker simply borrowed it in the moment. Any method that relies on a person reading a secret and typing it somewhere can be relayed this way.

What "phishing-resistant" actually means

The fix is not a stronger code or a smarter prompt. It is a method that removes the human's ability to hand the secret to the wrong site. That is the entire idea behind phishing-resistant MFA.

CISA's guidance on phishing-resistant authentication names two families. The first is modern FIDO2 and WebAuthn authenticators, which include passkeys built into phones and laptops and physical security keys. The second is certificate-based authentication such as smart cards. Both share one property: the credential is cryptographically bound to the legitimate website's exact address. When a user lands on a lookalike domain, the authenticator does not produce anything usable, because the address does not match. There is no code to phish and no prompt to fatigue. The proxy attack that defeats SMS and typed codes has nothing to relay.

This is also the direction of federal identity standards. The National Institute of Standards and Technology, in its digital identity guidance SP 800-63B, has for years distinguished authenticators by their resistance to interception and replay, and phishing resistance is the property that separates the strongest tier from the rest. The framing that public frameworks like the NIST Cybersecurity Framework reinforce is consistent: identity is a control surface, and not all controls on that surface are equal.

Why the insurance and regulatory pressure is following

The underwriting side has already noticed. Cyber insurers such as Coalition publish claims data showing that compromised credentials and business email compromise remain among the most frequent and expensive loss drivers, and both routes run straight through weak authentication. As carriers refine their questionnaires, "do you have MFA" is giving way to "what kind, and where," a shift we covered in why cyber insurance now requires MFA everywhere. A firm that answers "SMS codes on email" is increasingly answering a question the carrier already knows the weak side of.

Regulatory duties point the same way. Accounting practices handling customer financial information fall under the FTC Safeguards Rule, which requires multifactor authentication for anyone accessing customer information and pushes toward stronger implementations over time. Law firms handling regulated client data carry parallel obligations. In every case the same upgrade satisfies the control the regulator wants and the control the attacker cannot defeat, so one project serves both.

How a small firm should move, in order

Replacing MFA everywhere at once is neither necessary nor wise. Protect the logins with the largest blast radius first, then extend.

  1. Administrator accounts first. An attacker who defeats MFA on a standard user account has one mailbox. An attacker who defeats it on an admin account owns the tenant. Put phishing-resistant authentication, ideally a hardware security key, on every privileged login before anything else.
  2. Remote access and VPN next. Remote entry points are internet-facing and heavily targeted. These are exactly the surfaces carriers probe and attackers scan for, a pattern we described in what triggers a detailed cyber insurance questionnaire.
  3. Email third. Business email compromise starts here, and email is the recovery path for most other accounts. Passkeys on the primary email platform close the single most abused door in the small-business threat model.
  4. Retire SMS and simple push as you go. Turn off the weak methods once stronger ones are enrolled, so an attacker cannot fall back to the easy path. Leaving SMS enabled "just in case" hands the attacker the option you were trying to remove.

Deploying strong authentication is only half the job. Someone has to notice when a login still succeeds from the wrong place or a session token is used from an unexpected network, which is the detection layer we walk through in is your MDR provider watching, or just logging. Prevention and detection reinforce each other; neither alone is enough.

The box moved, and so should you

Turning on MFA was the right decision. The market has simply raised the bar since. SMS codes and one-tap prompts stop opportunistic attacks and satisfy an outdated checkbox, but they no longer stop the two techniques that drive real intrusions and real insurance claims. Phishing-resistant methods, built into the phones and laptops your team already carries, close that gap without a code to steal or a prompt to fatigue. Start with your administrators, work outward, and turn the weak methods off behind you. For the full control set underwriters now expect and how identity fits alongside the rest, start with the pillar guide on cyber-insurance defensible IT.

Get MFA that actually stops the attacks carriers now ask about.

The Carrier-Ready Bundle deploys phishing-resistant multifactor authentication across your admin, remote-access, and email logins, with the evidence trail underwriters expect. Schedule a free assessment to see where your current MFA leaves gaps.

See the Carrier-Ready Bundle