One-time codes from an authenticator app remain a big improvement over passwords alone, and they still block the bulk of automated credential-stuffing and password-spraying we see every week. But the threat has moved. Adversary-in-the-middle phishing kits now proxy the real login page, capture the code as the victim types it, and replay the resulting session token in seconds. The attacker never needs the password again, and the second factor is bypassed rather than broken.
The durable fix is phishing-resistant authentication: passkeys and FIDO2 security keys. Because these bind the credential to the real site origin, a proxied phishing page simply cannot complete the ceremony. Our recommendation for the next two quarters:
- Enrol privileged and administrator accounts on passkeys or hardware keys first — that is where the blast radius is largest.
- Shorten session lifetimes and require re-authentication for sensitive actions, so a stolen token expires quickly.
- Turn on conditional access / sign-in risk policies to flag impossible-travel and new-device logins.
- Keep authenticator-app MFA for the general population as you migrate — it is still far better than none.
If you would like a short assessment of where token theft would hurt most in your estate, and a staged rollout plan, we are happy to help.