CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods
Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.
The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All multi-factor authentication helps, but some kinds are much stronger than others.
Not all MFA is equal
Think of it as a ladder:
- Text message or phone call codes — better than nothing, but can be intercepted or phished.
- Authenticator app with number matching — much harder to abuse; the current baseline.
- Phishing-resistant methods (passkeys, security keys, Windows Hello) — cannot be tricked into working on a fake website.
Attackers now routinely use tools that relay codes and steal sessions in real time, which defeats the lower rungs.
The business impact
- Account takeover despite MFA, which surprises leadership who believed the risk was handled.
- Targeted attacks on administrators and executives, whose accounts are worth the effort.
Questions to ask your team
- What percentage of our employees still use text message codes?
- Do all administrators use phishing-resistant methods?
- What would it cost to give security keys to our highest-risk users?
What good looks like
Text messages phased out for most users, the authenticator app as the baseline, and phishing-resistant methods for admins, executives and finance staff — with a plan to expand them to everyone.
The decision
Fund phishing-resistant MFA for your top 10% highest-risk users this year. Passkeys on phones make it cheaper than it used to be.
- Reddit's Breach via SMS Interception (Aug 2018): Why SMS MFA Isn't Enough Incident Teardowns
- How to Migrate Users From SMS to Authenticator App and FIDO2 MFA How-To & Hardening
- Detecting SMS MFA Interception: Entra Sign-In Logs and Sentinel KQL Detection & Response