
How MFA gets hacked — and strategies to prevent it
The security benefits of multifactor authentication (MFA) are well-known, yet MFA continues to be poorly, sporadically, and inconsistently implemented, undercutting its effectiveness as a security tool while often saddling users with an extra workflow burden — one of many obstacles to MFA’s success.
Frequent news stories that describe innovative ways to circumvent MFA don’t help, such as evidence of an AI-fueled phishing attack that found cloud keys and SSH access details, and another case of an AI-based attack that leveraged Claude Code. Even the savviest vendors aren’t immune, as evidenced by a series of Okta attacks in 2023 that resulted in stolen GitHub source code, an infected supply ch...