Reported internet-crime complaints received by the FBI.
The expensive part is not the login. It is the unauthorized action after it.
Weak, phishable, or poorly configured authentication can expose payments, administrative changes, sensitive data, and machine-operated workflows to loss.
Reported losses across internet-crime categories, up 33% from 2023.
Global exposed losses reported for business email compromise, October 2013–December 2023.
Sources: FBI annual report release ↗ and FBI IC3 BEC alert I-091124-PSA (Sept. 11, 2024) ↗. These totals span many crime types and should not be represented as losses caused by MFA alone.
More factors do not automatically mean stronger authority.
Manual one-time codes can still be phished. Configuration gaps can bypass otherwise capable controls. Stronger systems bind the authenticator, the request, and the relying party cryptographically.
Password + code
- User can be tricked into relaying the proof
- Request details may not be bound to approval
- Shared secrets create attractive targets
Device key + signed request
- Origin and verifier can be bound to the ceremony
- Approval can include action, scope, and expiry
- The server verifies proof instead of receiving a reusable secret
NIST states that phishing resistance requires cryptographic authentication and does not treat manual-entry OTP methods as phishing-resistant. See NIST SP 800-63B guidance ↗.