MFA Under Fire: How Bad Actors Bypass Multifactor Authentication
Your OHIO account is valuable given it is often the gateway to your paycheck, your class data, or maybe even your highly confidential research. Stealing your username and password continues to be one of the top priorities of bad actors. Ohio University has Multifactor Authentication (MFA) enabled - isn’t that supposed to stop the attacker? This article explains how attackers bypass MFA and explores what you need to do to keep your account safe.
How Bad Actors Bypass MFA
It may come as a surprise, but attackers generally are not bypassing MFA by finding secret backdoors in authentication protocols and web applications. They actually are not bypassing MFA at all; instead, they simply ask the victim up front for the MFA approval in an attack called social engineering. In essence, after the victim has been tricked to share their username and password, they often go ahead and help the attacker get past MFA as well. There are various ways this could occur; for instance, the attacker could initiate an MFA Fatigue attack where they continue to initiate a phone call to your phone number until you answer and approve the request. Or they may set up fake login pages to encourage you to sign in to the page and intercept your authenticated session using an attack called Adversary in the Middle Phishing.
SMS and Phone Authentication Less Secure
Microsoft is making changes to multi-factor authentication (MFA) to improve account security and reduce reliance on authentication methods that are more vulnerable to phishing and fraud. As part of this initiative, Microsoft-provided SMS text message and phone-call authentication methods will no longer be supported beginning February 1, 2027.
To prepare for this change, Ohio University is encouraging users to enroll in the Microsoft Authenticator app, which provides a more secure and convenient way to verify your identity when signing in.
How Can I Keep My OHIO Account Safe
For National Cybersecurity Awareness Month, the Information Security Office will share additional articles on how to protect your account by recognizing phishing attempts, keeping your software up to date, how to protect your data while traveling, and how to upgrade from traditional password logins to a more secure form of authentication. Following these tips will help keep your account safe.
The Future of Passwords: Passwordless Logins Sneak Peek
Too eager to wait for upcoming articles and ready to move away from boring password logins? Check out our knowledge base article about Microsoft Authenticator Passkeys(opens in a new window) and Passwordless Authentication(opens in a new window).