Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Not All MFA Is Equal — The Case for Phishing-Resistant Methods

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2018, written in 2026 with the benefit of hindsight.

The short version: In 2018, Reddit was breached even though its employees used two-factor authentication — the attacker intercepted text message codes. All multi-factor authentication helps, but some kinds are much stronger than others.

Not all MFA is equal

Think of it as a ladder:

  1. Text message or phone call codes — better than nothing, but can be intercepted or phished.
  2. Authenticator app with number matching — much harder to abuse; the current baseline.
  3. Phishing-resistant methods (passkeys, security keys, Windows Hello) — cannot be tricked into working on a fake website.

Attackers now routinely use tools that relay codes and steal sessions in real time, which defeats the lower rungs.

The business impact

  • Account takeover despite MFA, which surprises leadership who believed the risk was handled.
  • Targeted attacks on administrators and executives, whose accounts are worth the effort.

Questions to ask your team

  • What percentage of our employees still use text message codes?
  • Do all administrators use phishing-resistant methods?
  • What would it cost to give security keys to our highest-risk users?

What good looks like

Text messages phased out for most users, the authenticator app as the baseline, and phishing-resistant methods for admins, executives and finance staff — with a plan to expand them to everyone.

The decision

Fund phishing-resistant MFA for your top 10% highest-risk users this year. Passkeys on phones make it cheaper than it used to be.

reddit breach sms 2fa impactReddit SMS 2FA2018

More on this story