logo

The Hidden Risks of SMS-Based Multi-Factor Authentication by Lucie Cardiet

ID: 06d59a6d-d8ad-5393-a7d0-d839c0eb17c7

STIX ID: report--06d59a6d-d8ad-5393-a7d0-d839c0eb17c7

Feed Name: Vectra AI Blog

Threat Score
70/100

Date Published: 2024-01-19

Date Updated: 2026-05-01

...
...

**Executive summary:** This blog explains why SMS-based two-factor authentication is no longer a defensible enterprise control, demonstrates real-world failures (phone number recycling and account takeover), and details attacker playbooks—SIM swapping, social engineering, and mass-number exploitation—used by groups such as Scattered Spider to bypass MFA, escalate privileges, establish persistence in cloud environments, and exfiltrate or monetize access; it recommends replacing SMS MFA with phishing-resistant methods (FIDO2/passkeys/security keys) and continuous identity monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.