Phishing-Resistant MFA

Phishing-Resistant MFA is the term for multi-factor authentication methods whose proofs cannot be intercepted via fake login pages and reused by attackers. This is achieved through cryptographic methods that technically bind the login to the legitimate service.

Conventional second factors such as SMS codes, one-time passwords from apps or push confirmations increase security, but can be captured in real time via adversary-in-the-middle attacks or circumvented through MFA fatigue, i.e. repeated push requests until a user agrees. Phishing-resistant methods prevent this because the authenticator checks the domain of the service and does not generate a valid proof on a fake page. According to the classification of the US cybersecurity agency CISA, methods based on FIDO2 and WebAuthn as well as PKI-based smart cards are considered phishing-resistant in particular.

The NIST guideline SP 800-63B requires phishing-resistant authenticators for assurance level AAL3; many security programs use them specifically for privileged and particularly exposed accounts. In everyday use, they are mostly used as Passkeys or hardware security keys. Phishing-resistant MFA is a further development of classic Multi-Factor Authentication (MFA) and a core building block of Identity Security.