{"id":8149,"date":"2026-09-28T06:45:00","date_gmt":"2026-09-28T10:45:00","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=8149"},"modified":"2026-09-03T11:38:57","modified_gmt":"2026-09-03T15:38:57","slug":"what-actually-counts-as-mfa","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/what-actually-counts-as-mfa\/","title":{"rendered":"What Actually Counts as MFA?"},"content":{"rendered":"\n<p><strong>\u201cWe have MFA\u201d gets treated as a single answer, checked once and forgotten. It shouldn\u2019t be. SMS codes, authenticator app codes, and hardware security keys are all called MFA, and they stop very different attacks. A firm running SMS-based codes on every account has technically satisfied \u201cMFA required.\u201d A real, determined attacker still has a way through. Here\u2019s what each tier actually defends against.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p><strong>Key takeaways<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SMS-based MFA can be defeated through SIM swapping, without the attacker ever touching the account holder\u2019s actual phone.<\/li>\n\n\n\n<li>A real-time phishing attack can defeat both SMS codes and authenticator app codes by relaying them to the real site within seconds.<\/li>\n\n\n\n<li>Hardware security keys and passkeys are the only widely available MFA type built to resist that real-time relay attack specifically.<\/li>\n\n\n\n<li>Cyber insurers increasingly ask which specific type of MFA a firm has deployed, going well beyond a yes or no.<\/li>\n\n\n\n<li>MFA needs to be enforced everywhere client data lives, including accounts that don\u2019t have it turned on yet.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#why-we-have-mfa-doesnt-answer-the-real-question\">Why \u201cwe have MFA\u201d doesn\u2019t answer the real question<\/a><\/li><li><a href=\"#the-three-tiers-and-what-each-one-actually-stops\">The three tiers, and what each one actually stops<\/a><\/li><li><a href=\"#the-attack-that-gets-past-sms-and-authenticator-apps-alike\">The attack that gets past SMS and authenticator apps alike<\/a><\/li><li><a href=\"#why-insurers-and-auditors-are-starting-to-ask-which-kind\">Why insurers and auditors are starting to ask which kind<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-we-have-mfa-doesnt-answer-the-real-question\"><strong>Why \u201cwe have MFA\u201d doesn\u2019t answer the real question<\/strong><\/h2>\n\n\n\n<p><strong>MFA means a second proof of identity beyond a password. It doesn\u2019t specify what that second proof actually is. The gap between the options is larger than the shared label suggests.<\/strong><\/p>\n\n\n\n<p>A text message code, a code from an authenticator app, and a physical security key all satisfy a checkbox that says \u201cMFA enabled.\u201d None of them satisfy the same threat model. Treating them as interchangeable is how a firm ends up technically compliant while still exposed to the exact attack MFA was supposed to stop.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-three-tiers-and-what-each-one-actually-stops\"><strong>The three tiers, and what each one actually stops<\/strong><\/h2>\n\n\n\n<p><strong>SMS codes stop a stolen password used on its own. Authenticator app codes stop most automated credential-stuffing attacks. Hardware security keys and passkeys stop those attacks plus the real-time phishing relay that gets past the first two.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-1024x576.jpg\" alt=\"SIM swap redirecting mobile codes cinematic visual | Verito\" class=\"wp-image-8162\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-sim-swap.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>MFA type<\/th><th>What it actually stops<\/th><th>Where it falls short<\/th><\/tr><\/thead><tbody><tr><td>SMS code<\/td><td>A stolen password used on its own<\/td><td>Defeated by SIM swapping, no phishing resistance<\/td><\/tr><tr><td>Authenticator app code<\/td><td>Stolen password, SIM swapping<\/td><td>Defeated by real-time phishing relay<\/td><\/tr><tr><td>Hardware key or passkey<\/td><td>All of the above, plus real-time relay<\/td><td>Requires a physical device or platform support<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>SIM swapping means an attacker convinces a mobile carrier to move a phone number onto a device they control. The attacker then receives SMS codes meant for someone else, without ever touching that person\u2019s actual phone. An authenticator app closes that specific gap, since its code generates locally on the device rather than traveling over the phone network.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"the-attack-that-gets-past-sms-and-authenticator-apps-alike\"><strong>The attack that gets past SMS and authenticator apps alike<\/strong><\/h2>\n\n\n\n<p><strong>A real-time phishing relay works differently than a normal phishing email. It presents a fake login page, captures the password and MFA code as the victim types them, and passes both to the real site within seconds.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-1024x576.jpg\" alt=\"Hardware security key stopping phishing relay cinematic visual | Verito\" class=\"wp-image-8163\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/what-actually-counts-as-mfa-phishing-resistant.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Neither SMS nor a standard authenticator app was built to resist this specific attack. Both produce a code that works for anyone who enters it in time, including an attacker relaying it live. Hardware security keys and passkeys close this gap through a different mechanism. The device itself verifies it\u2019s talking to the real site before it responds. A relayed request from a fake page gets rejected automatically instead of passed through.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-insurers-and-auditors-are-starting-to-ask-which-kind\"><strong>Why insurers and auditors are starting to ask which kind<\/strong><\/h2>\n\n\n\n<p><strong>Cyber insurance applications increasingly ask which specific type of MFA a firm has deployed. SMS-based codes are treated as a weaker answer than authenticator apps or hardware keys, and some carriers ask about phishing-resistant MFA by name.<\/strong><\/p>\n\n\n\n<p>That mirrors what a <a class=\"wpil_keyword_link\" href=\"http:\/\/verito.com\/written-information-security-plan\" target=\"_blank\" rel=\"dofollow noopener\" title=\"WISP\" data-wpil-keyword-link=\"linked\" data-wpil-monitor-id=\"1387\">WISP<\/a> built to IRS Publication 4557 and the FTC Safeguards Rule already expects. <a href=\"https:\/\/verito.com\/cyber-insurance-checklist\/\" target=\"_blank\" rel=\"dofollow\" >MFA belongs on every account that touches client data<\/a>, enforced consistently rather than turned on for some accounts and skipped for others. <a href=\"https:\/\/verito.com\/hosting\/\" target=\"_blank\" rel=\"dofollow\" >VeritSpace enforces MFA on every user login by default<\/a>. VeritGuard extends that same enforcement across Microsoft 365, Google Workspace, and VPN connections. The answer to which type of MFA a firm uses shouldn\u2019t depend on which account someone happened to set up first.<\/p>\n\n\n\n<p><a href=\"https:\/\/verito.com\/contact\/\" target=\"_blank\" rel=\"dofollow\" ><strong>Talk to us about closing the gaps in your firm\u2019s MFA coverage \u2192<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"\u201cWe have MFA\u201d gets treated as a single answer, checked once and forgotten. It shouldn\u2019t be. SMS codes,&hellip;\n","protected":false},"author":12,"featured_media":8161,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-8149","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=8149"}],"version-history":[{"count":3,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8149\/revisions"}],"predecessor-version":[{"id":8411,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8149\/revisions\/8411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8161"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=8149"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=8149"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=8149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}