← All terms

Phishing-Resistant MFA

Phishing-resistant MFA is multi-factor authentication that cannot be captured or relayed by a fake login page — in practice, FIDO2 security keys and passkeys bound cryptographically to the legitimate domain.

Phishing-resistant MFA is multi-factor authentication designed so that there is nothing a phishing site can steal or replay. Codes, push approvals and SMS all produce a secret or a decision the user can be tricked into handing over; phishing-resistant methods — FIDO2 security keys and passkeys — replace that with a cryptographic exchange bound to the real website's domain, so a fake login page simply cannot complete it.

How it works

With FIDO2/WebAuthn, the user's device holds a private key and the service holds the matching public key. At login, the browser signs a challenge that includes the site's origin. A proxy site on a lookalike domain receives a signature that is invalid for the real service, and there is no code to read, type, or approve — the human is no longer carrying a secret between two screens.

Contrast that with the methods attackers have learned to beat. Adversary-in-the-middle kits relay a victim's password and one-time code to the real site in real time and steal the authenticated session cookie. MFA fatigue bombards a user with push prompts until one is approved. SIM swapping intercepts SMS codes. Each of these defeats possession-based MFA by exploiting the human step; none of them works against an origin-bound credential. Agencies including CISA and NIST now explicitly distinguish phishing-resistant methods from the rest, and recommend them for high-risk accounts first.

How to defend

  • Prioritize by blast radius. Move administrators, executives, finance and help-desk staff to FIDO2 keys or passkeys first — the accounts attackers target with MFA bypass techniques.
  • Close the fallback hole. A phishing-resistant front door means little if account recovery still accepts an SMS code or a help-desk password reset; attackers go where the weak factor remains. Our MFA fatigue guide and enterprise passkey migration guide cover the rollout sequence.
  • Pair the control with training. Users should understand why the prompt disappeared — and that any login flow asking them to read a code to a caller is an attack, not a recovery process.

Related terms

Multi-Factor Authentication (MFA)Multi-factor authentication (MFA) requires two or more independent proofs of identity to log in, so a stolen password alone is not enough for account access.PasskeyA passkey is a phishing-resistant FIDO2/WebAuthn credential — a cryptographic key pair bound to one website — that replaces passwords and one-time codes.MFA BypassMFA bypass is any technique that defeats multi-factor authentication — from push fatigue and AiTM proxies to help desk resets and SIM swapping.Adversary-in-the-Middle (AiTM)An adversary-in-the-middle (AiTM) attack proxies a real login page to steal both credentials and the session token issued after MFA is completed.MFA Fatigue AttackAn MFA fatigue attack bombards a user with repeated multi-factor authentication push notifications until they approve one out of frustration or confusion.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo