
Introduction
Multi-factor authentication (MFA) is one of the most widely recommended security controls. And rightly so.
But having MFA enabled does not necessarily mean your organisation is protected against modern phishing.
The uncomfortable reality in 2026 is that many MFA methods protecting executives, finance teams and administrators can be bypassed by phishing kits available for a few hundred euros.
The question is therefore changing from “Do we have MFA?” to “Do we have the right MFA?”
How attackers bypass traditional MFA
One of the biggest changes in identity attacks is the rise of Adversary-in-the-Middle (AiTM) phishing.
Instead of simply creating a fake login page, the attacker places a transparent proxy between the user and the real authentication service.
The user sees what appears to be the legitimate Microsoft login page, enters a password and approves a push notification or enters an authentication code. The legitimate service then issues a valid session token — which the attacker captures.
The password was correct. The MFA was completed. And the account was still compromised.
Taking down one operator does not take down the technique.

The anatomy of an AiTM attack
Three tiers of MFA protection
Not all MFA methods offer the same level of protection. The critical difference is which attack vectors each method is exposed to and whether it can withstand modern phishing techniques such as AiTM attacks.

MFA methods
| Method | Tier | Main attack vectors | Phishing resistant? |
|---|---|---|---|
| Email OTP | 🔴 EXPOSED | Mailbox compromise, forwarding rules, interception and real-time AiTM proxy | No |
| SMS / Voice OTP | 🔴 EXPOSED | SIM swap, SS7 interception and real-time AiTM proxy | No |
| TOTP codes | 🟠 BYPASSABLE | Real-time AiTM proxy | No |
| Hardware OTP tokens | 🟠 BYPASSABLE | Real-time AiTM proxy; the user still retypes a code | No |
| Push notifications | 🟠 BYPASSABLE | MFA fatigue and real-time AiTM proxy | No |
| FIDO2 passkeys, Windows Hello for Business, smart cards and certificate-based authentication | 🟢 PHISHING RESISTANT | Origin-bound authentication. Residual risks include token theft, enrolment abuse and endpoint compromise | Yes |
The key distinction is architectural. Email and SMS are exposed because they can be intercepted remotely. TOTP, hardware tokens and push notifications are stronger, but can still be relayed through an AiTM proxy. Number matching helps prevent MFA fatigue, but does not stop this type of attack.
Phishing-resistant methods work differently. Passkeys, Windows Hello and certificate-based authentication bind the authentication to the legitimate service, leaving no reusable code for an attacker to intercept and relay.
That is the difference between simply having MFA and having MFA that can resist modern phishing attacks.
And what about Europe?
For European organisations, compliance does not necessarily mean phishing-resistant:
- NIS2 & ENISA: require MFA where appropriate and based on risk, but do not prescribe FIDO2 or phishing-resistant authentication.
- Belgium’s CyberFundamentals: follows the same risk-based approach, with no specific FIDO2 requirement.
- DORA: requires strong authentication for sensitive access but remains technology-neutral.
- PSD2: shows the gap clearly – SMS OTP can meet strong customer authentication requirements while still being vulnerable to real-time phishing.
- eIDAS 2.0: introduces wallet-bound credentials with principles similar to WebAuthn, but follows a separate standards track.
The takeaway: European regulation tells you to use MFA, but not which MFA will withstand today’s attacks. Compliance is the baseline; phishing resistance is a security decision.
The market is already moving
Technology providers are moving towards phishing-resistant authentication regardless.
Microsoft has also announced that passkeys become the default authentication method in Entra ID from 1 September 2026, with Microsoft-provided SMS and voice authentication scheduled for retirement on 1 February 2027.
The FIDO Alliance counted around five billion passkeys in use by May 2026.
The technology is no longer experimental. The challenge now is migration and adoption.
What should organisations do?
Start with the users and systems where compromise would hurt most.
- Protect privileged users first. Move administrators, executives, finance teams and other high-risk users to phishing-resistant authentication.
- Enforce the right methods. Use conditional access to require phishing-resistant authentication for sensitive systems and remove weaker fallback methods where possible.
- Protect enrolment and recovery. Monitor new authenticator registrations and strengthen help-desk identity verification.
- Reduce the value of stolen sessions. Use token protection, continuous access evaluation and appropriate session lifetimes.
- Don’t forget machine identities. Service accounts, API keys and increasingly AI agents cannot use traditional MFA. They require their own identity governance, least privilege and credential lifecycle management.
- Test your actual environment. AiTM phishing, device-code attacks and help-desk social engineering should be part of realistic security testing.
Final thoughts
MFA is not a checkbox.
The authentication method that was considered strong enough a few years ago may no longer provide meaningful protection against today’s phishing infrastructure.
Phishing-resistant authentication changes that equation, but it also moves attackers towards sessions, enrolment, OAuth and non-human identities.
So the question for organisations in 2026 is no longer simply whether MFA is enabled.
It is whether the MFA you have actually protects you against the attacks you face today.
For more on what the latest Salesforce MFA changes mean for organisations, read our article: Salesforce MFA Enforcement 2026: What Every Organisation Needs to Know.
At asUgo, we help organisations turn that question into a practical identity security strategy, assessing existing authentication methods, identifying where stronger controls are needed, and defining a realistic path towards phishing-resistant authentication without compromising the user experience.
Want to understand where your organisation stands? Get in touch with our Cyber & Privacy team.
Sources:
- IBM, Cost of a Data Breach Report 2025
- Verizon, 2025 Data Breach Investigations Report
- Akamai, State of the Internet: Ransomware Trends 2025
- CrowdStrike, 2026 Global Threat Report
- Centre for Cybersecurity Belgium (CCB), Cyber Threat Landscape Belgium 2025
- CrowdStrike, 2025 European Threat Landscape Report
- Sophos, The State of Ransomware 2025
Author: Robin Descamps, Head of Security, asUgo



