Okta saw a record number of attacks targeting multi-factor authentication (MFA) in the first half of 2022, which underscores the importance of correctly installing MFA and in selecting strong secondary factors.

The identity and access management vendor observed more than 100 million MFA attacks through its Auth0 platform in the first 90 days this year, according to its latest State of Secure Identity Report. It noted  threat actors are becoming more sophisticated at targeting authentication resulting in application and service providers recommending or requiring MFA.

“When most organizations implemented MFA-based authentication mechanisms to defend from identity-based attacks, they did so using low assurance factors such as secret questions, SMS, voice-, and email-based one-time passwords (OTP), and still relied heavily on the password being a bootstrap or primary authenticator,” Sumit Bahl, director of product marketing at Okta, wrote in response to questions.

“Subsequently, the attack methods of the bad actors have evolved to target authentication factors that are perceived to be secure but are not, SMS-based OTP for instance,” Bahl added.

How to Prevent MFA Bypass

During several recent data breaches and network hacks, MFA was bypassed by intruders.

Okta pointed that besides manual approaches such as SIM swapping and social engineering, compromising a strong MFA would need the target’s account credentials and pass the MFA using a secondary proof of identity.

If the target uses weak secondary factors, “attackers can try to bypass MFA using techniques that either downgrade MFA to single-factor authentication, intercept the second factor, or disable/weaken an organization's ability to enforce MFA policies such as modifying trusted IP configurations or session reuse, for instance,” Bahl explained.

In a recent attack targeting Cisco, the attacker used techniques including a series of sophisticated voice phishing (vishing) attacks and sending a high volume of MFA push requests. Ultimately, the victim accepted the MFA push notifications and the attacker gained access to the Cisco VPN.

The technique takes advantage of MFA fatigue when a user gets fed up with notification prompts and accepts one to stop the flooding notifications, Bahl noted. 

To reduce the susceptibility to MFA bypass attacks, Bahl recommends redesigning security policies to replace weak authenticators with phishing resistance authenticators for MFA such as FIDO Alliance protocols, eliminating the reliance on passwords, and adding another layer of risk-based authentication that requires a stronger authenticator for logins to sensitive applications.