Strong Passwords Weren’t Enough. Now Plain MFA Isn’t Either.

In 2003, a manager at the National Institute of Standards and Technology (NIST) named Bill Burr wrote the guidance that shaped password policy for the next fifteen years. Capital letters, numbers, special characters; change it every 90 days. If you’ve ever typed something like Summer2019! into a work computer, that’s his memo at work. In 2017 he told the Wall Street Journal he regretted most of it.

He wasn’t wrong for the era. He was wrong about how attackers would adapt. And that pattern, a defense that worked until attackers stopped playing along, is the whole story of this post. It happened to passwords. It’s happening to multi-factor authentication (MFA) right now.

The Password Era, and How it Ended

Complex passwords were built to stop guessing. What killed them wasn’t guessing, it was reuse and theft. Big breaches dumped hundreds of millions of real passwords onto the internet, and people use the same password for their bank, their email, and the scheduling system at work. Attackers stopped cracking passwords and started logging in with them.

By 2017, NIST itself had reversed course, dropping the forced rotation and special character rules. The new advice was longer passwords, no forced changes, and, more importantly, don’t rely on the password alone.

MFA Was the Answer

MFA fixed the reuse problem directly. A stolen password wasn’t enough anymore, because the attacker also needed the code from your phone. Microsoft published research in 2019 saying MFA blocked over 99.9 percent of automated account attacks, and cyber insurers took notice. If your business renewed a policy anytime in the last few years, you saw the question: do you require MFA on email and remote access? Answer no, and your premium went up, or the quote never came at all.

For a 20-person manufacturer or a small law office, turning on MFA was the single biggest security upgrade of the decade. That’s still true. If you don’t have it, stop reading and go turn it on.

But the same thing that happened to passwords is happening again. Attackers adapt, and the most common forms of MFA have a weakness: they depend on a person making the right call in the moment.

How Cyber Attackers Get Past Now

Three techniques do most of the damage.

Prompt Bombing 

The attacker already has your password and triggers login attempt after login attempt, flooding your phone with approval prompts at 11 p.m. until you tap yes just to make it stop. This is how Uber got breached in 2022. The attacker then messaged the employee pretending to be IT and talked him into approving.

Real-Time Relay

You click a link in a convincing email and land on a login page that looks exactly right. You type your password and your six-digit code. The fake page passes to the real site instantly, and the attacker is in. You even end up logged in yourself, so nothing feels off. The code did its job. It just did it for the wrong person.

SIM Swapping

For codes sent by text message, the attacker convinces the phone carrier to move your number to their device. Your codes go to them. This one takes more effort, however, it is why text-message codes are considered the weakest form of MFA.

Notice what all three have in common. None of them break the technology. They work because a human can be rushed, tired, or fooled, and the code or prompt doesn’t know the difference.

What Phish-Resistant Means

Phish-resistant MFA takes the human judgment call out of the login. The main version you’ll hear about is the passkey, sometimes called FIDO2. It can live on your phone, in Windows Hello on your laptop, or on a small hardware key that costs about $25 and sits on your keychain.

The difference is that a passkey is locked to the real website’s identity. When you set one up for your Microsoft 365 account, it will only ever answer to the genuine Microsoft login page. Put a pixel-perfect fake website in front of it and the passkey simply doesn’t respond. There’s no code to type into the wrong box, no prompt to approve at 11 p.m., nothing an attacker can intercept and relay. All three techniques fail for the same reason: not because you caught the scam, but because there was nothing to catch.

This isn’t exotic. The phone in your pocket already supports passkeys. Microsoft 365 supports them today, and CISA, the federal cybersecurity agency, has been recommending phish-resistant MFA since 2022. Insurance questionnaires are beginning to ask about it by name.

What Action You Should Take

Nobody needs to rip out their current MFA this quarter. The move is to upgrade where the stakes are highest first: email accounts, because email resets everything else, and administrator accounts, because those hold the keys to the whole environment. Owners and bookkeepers who approve payments belong near the front of the line too, since they’re who the fraudulent wire requests target.

From there it can roll out gradually, the same way MFA itself did a few years ago.

The Short Version

Strong passwords were the standard until stolen credentials made them insufficient on their own. MFA closed that gap and became the insurance requirement. Now attackers have learned to talk their way past codes and prompts, and the standard is moving again, toward logins that can’t be phished because there’s nothing to steal. The businesses that moved to MFA early skipped a lot of pain. Same opportunity here.

If your business is ready to move beyond codes and prompts to phish-resistant MFA, Advanced Technology Partners can help. As a full-service outsourced IT department, we provide managed IT support and cybersecurity solutions for businesses in Youngstown and beyond, built around proactive monitoring and cyber-threat detection. Reach out to ATP to find out how secure your business is and build a plan to get to phish-resistant MFA support.

Frequently Asked Questions

Do I need to replace my current MFA right away?
No. Phish-resistant MFA is a rollout, not a rip-and-replace. Start with the accounts that carry the most risk, like email and administrator logins, then expand from there. ATP’s Cybersecurity & Compliance team can help you map out which accounts to prioritize first.

Does a passkey cost anything?
Not necessarily. Passkeys can live in your phone or in Windows Hello on a laptop you already own, both at no added cost. A physical hardware key is optional and runs around $25 if you want one for a shared device or a high-privilege account.

Will switching to passkeys slow my team down?
It’s usually the opposite. Signing in with a fingerprint or face scan is faster than typing a six-digit code, and there is nothing to type wrong or wait on. ATP’s Managed IT Services team handles setup, so your staff sees a smoother login, not a harder one.

Does my insurance care whether my MFA is phish-resistant?
Not yet across the board, but it’s moving that direction. Insurers already ask whether MFA is enabled at all, and some questionnaires are starting to ask about phish-resistant methods by name. Getting ahead of it now means one less thing to scramble for at renewal.

Recent Posts

Strong Passwords Weren’t Enough. Now Plain MFA Isn’t Either.

Advanced Technology Partners Earns Ranking on MSP List

Backups vs. BCDR: What’s the Difference for Your Business

Advanced Technology Partners Sees Client, Team Growth

Reach Out

Ready to simplify your business IT needs?

Skip the wait — our experts are ready to help right now.