2FA attacks: we measure whether the second factor survives a proxy

An intermediary asks for the code or the push in real time. The exercise is technical: which control fails, not who “fell for an SMS”.

How it works

How we test the factor without breaking the IdP

Second-factor map

We document which MFA the roles in the universe use: app, OTP, push, key. Without that map the scenario is generic and does not measure. IAM has to sit in the brief.

Intermediary design

We build the proxy or challenge-capture flow without persisting secrets. The lure looks like the login people already use. The ethical cap is not reusing a real session and not touching IdP production.

Bounded execution

We fire the lure at the agreed universe. We log who handed over the code, who approved the push and who stopped to verify on another channel. There is no mass marketing SMS blast.

Control reading

The report turns the gesture into a control: fatigue, no matching, SMS OTP, no FIDO. Security and IAM get the same piece, in architecture language, not awareness-campaign language.

Why it matters

Why “we already have MFA” is an incomplete sentence

Because the second factor was designed for an attacker who is not in the session. The intermediary is: they see the challenge and pass it on. The OTP that travels by SMS or is read out loud is a one-time secret the proxy spends in the same…

Why “we already have MFA” is an incomplete sentence
Deliverables

What you get

Evidence of whether the second factor holds against an intermediary, written for IAM and for the program.

MFA map of the universe

Which factor each in-scope role uses. Without it the result cannot be read. It stays as an annex to the report.

Intermediary scenario

A controlled flow, no persisted secret, aligned to your IdP in appearance and not in production credentials.

Control report

Who handed over the factor and which control failed. A technical cut, not a “fell for phishing” rate.

Habit and architecture recommendation

What to ask of people (do not approve a blind push, do not read the OTP) and what to decide in IAM (matching, FIDO, out-of-band). Two lines, one owner each.

Requirements and timelines

What we need from you

  • An IAM or identity counterpart who can explain the real second factor, not the one in the policy. Access to a lookalike environment — IdP branding, challenge copy — without…
  • Also a universe of people who actually use MFA. A group still on password-only is useless. Exclusions: service accounts, break-glass, third parties. This service does not ask for…
The program

How it fits the program

The 2FA attack does not replace email simulations or smishing. It is a measurement of the factor, not of the personal phone and not of an attachment click. It is read with IAM and with the index, in two different…

How it fits the program
Questions

Questions about 2FA attacks

Is this the same as credential phishing?
No. The object is the second factor and the mechanism is the intermediary. A click on a password email does not answer whether MFA holds.
Do you touch our production IdP?
No. The flow is lookalike and controlled capture. We do not reuse real sessions or persist secrets.
Does it work if MFA is a hardware key?
The scenario is redesigned: the gesture is no longer handing over an OTP. Scope declares what can be measured and what cannot. We do not promise a hardware bypass.
Is it an exercise for the whole roster?
It is usually a technical universe or exposed roles, not a mass campaign. IAM defines the cut with security.
Is there a price on the site?
No. It depends on the factor, the universe and the intermediary design. It is quoted.

Put the sentence “we have MFA” to the test

If the second factor was never measured against an intermediary, coverage is a hypothesis. Let’s talk with IAM.

Full catalog on Services