Skip to content

The MFA Level Up: Why SMS Codes Are No Longer Enough

Laptop on a clean desk with USB security key plugged in to illustrate stronger MFA methods.

Multi‑Factor Authentication (MFA) has been a cornerstone of account security for years, and for good reason. Adding a second factor dramatically reduces the risk of account compromise. But not all MFA methods offer the same level of protection, and the threat landscape has moved on. For many organisations, SMS one‑time codes are still the default. They’re familiar, easy to deploy, and certainly better than passwords alone. However, SMS was never designed as a secure authentication channel. Techniques like SIM‑swap fraud, number porting scams, and real‑time phishing have made SMS‑based MFA increasingly easy for attackers to bypass. In New Zealand, SIM‑swap scams remain a common fraud method, and once an attacker controls a phone number, SMS codes offer little protection. For organisations handling sensitive data or critical systems, SMS MFA is no longer enough on its own.

Why Phishing‑Resistant MFA Matters

Modern attacks don’t just steal passwords, they trick users into handing over MFA codes in real time. To counter this, security is shifting toward phishing‑resistant MFA, which removes the need for users to type codes at all. Phishing‑resistant MFA relies on cryptographic authentication tied to a specific service or domain. One widely adopted approach is the FIDO2 standard, which uses public‑key cryptography to ensure login attempts only succeed on legitimate sites. Even if a user clicks a convincing phishing link, their credentials won’t work because the authentication request doesn’t match the real service. This significantly raises the bar for attackers and reduces the impact of human error – still one of the biggest risk factors in security incidents.

Hardware Security Keys and Phishing-Resistant MFA

One of the most effective forms of phishing‑resistant MFA is a hardware security key. These are small physical devices (often USB or NFC) that perform a secure cryptographic check when you log in. There are no codes to intercept and nothing for an attacker to reuse remotely. Advantage works closely with Yubico, the creators of YubiKey, whose hardware security keys are widely recognised as the gold standard for phishing‑resistant authentication. YubiKeys are purpose‑built to support standards such as FIDO2 and are used globally to protect high‑risk users, administrators, and privileged accounts. Hardware keys such as YubiKeys are particularly well suited for administrators, executives, and anyone with access to high‑risk systems. Unless the key itself is physically stolen, attackers can’t use it – even if they have the password – making them an effective control against phishing, MFA fatigue, and credential replay attacks. For users who aren’t ready for hardware keys, modern authenticator apps are a strong step up from SMS. Apps like Microsoft Authenticator generate codes locally on the device, eliminating the risk of SMS interception. Many now include protections such as number matching, which prevents “MFA fatigue” attacks where users are spammed with approval prompts until they click yes.

Passkeys: Where Authentication Is Headed

Looking ahead, passkeys are becoming the preferred authentication method across major platforms. Passkeys are stored securely on a device and unlocked using biometrics, such as a fingerprint or face scan. They offer the security benefits of hardware‑backed authentication with the convenience of devices people already carry. As support for passkeys continues to grow across cloud services and identity platforms, they are expected to significantly reduce (and in some cases remove) reliance on passwords altogether. Instead of asking users to remember and type credentials that can be stolen or reused, authentication becomes tied to devices, biometrics, and cryptographic proof that attackers can’t easily replicate.

Security That Improves UX

Stronger MFA doesn’t have to mean more friction. In fact, when implemented well, modern authentication methods can reduce user frustration while materially improving security. By choosing the right mix of phishing‑resistant controls, organisations can lower risk, simplify access, and build a more resilient identity layer without slowing people down.

Facebook
Twitter
LinkedIn

Related Posts

Ask ten business leaders what their AI governance strategy is and you’ll probably get ten very different answers. Find out where your organisation sits.
We often talk about “the cloud” as if business data simply disappears into the internet. In reality, cloud services depend on very physical foundations. At the heart of Advantage Cloud is our data centre.
When users complain that systems are slow, the immediate response is often to question the internet connection. But increasingly, organisations are discovering that the real bottleneck sits much closer to home – the firewall.