Why standard text and app codes no Longer protect your business accounts
Standard two-step verification like text messages or app push notifications no longer stops sophisticated phishing attacks that steal active login sessions, according to security researchers and identity providers. Small businesses using Microsoft 365 can protect their accounts by switching to hardware security keys or passkeys, which verify the website's identity before allowing a login.
Standard two-step verification like text messages or app push notifications no longer stops sophisticated phishing attacks that steal active login sessions, according to security researchers and identity providers. Small businesses using Microsoft 365 can protect their accounts by switching to hardware security keys or passkeys, which verify the website’s identity before allowing a login.
Adversary-in-the-middle (AiTM) phishing kits now act as a relay between a user and a real login page, capturing session cookies the moment authentication finishes. Security researchers note these tools have moved from elite capabilities to commodity tooling, making them widely available to attackers.
Standard multi-factor authentication methods like SMS codes, authenticator apps, and push notifications can’t distinguish between a real login page and a fake proxy site. Okta’s identity security team explains that these methods lack the ability to verify the domain, allowing attackers to capture credentials and session cookies undetected.
A separate technique called device-code phishing tricks users into authorizing an attacker’s session directly, often disguised as a meeting invite or IT verification step. This method bypasses password theft entirely by abusing legitimate authentication protocols.
The Government of Canada’s Cyber Centre states that phishing-resistant multi-factor authentication prevents these campaigns by cryptographically binding the authenticator to the specific domain. This ensures that a proxy on a look-alike domain is refused access.
FIDO2 security keys and passkeys provide the necessary protection because they check the domain before releasing a signed assertion. The UK’s National Cyber Security Centre notes that passkeys are resistant to phishing because they can’t be intercepted, reused, or stolen like passwords.
Steps to secure your office accounts
If you run a dental office, law firm, or accounting practice, your front-desk PC and email accounts are the target. Here’s what you need to do this week.
- Audit your current accounts to identify which staff members are still using SMS or app-based push notifications, as these are vulnerable to session theft.
- If you use Microsoft 365, ensure you have Entra ID P1 or P2 licensing, which is bundled with Business Premium, to access conditional access policies.
- Create a baseline conditional access policy in the Entra admin center to require multi-factor authentication for all users, setting it to ‘Report-only’ mode first to monitor impact.
Purchase FIDO2 hardware security keys for your administrative accounts and enable passkey registration for pilot users in the authentication policies.
Plan a phased rollout over four to eight weeks to allow staff time to adapt to the new login methods, starting with privileged accounts like admins and finance approvers.
The fix is boring and it works. Worth an hour of someone’s Friday to stop a weekend of cleanup.
Sources: tech-insider.org.
3DPrintStack
Stop losing money on underpriced jobs
Filament tracking, print queue, real cost per print, and a P&L that shows which jobs actually pay.
One plan · $20/month · 14-day free trial