2FA attacks: we measure whether the second factor survives a proxy
An intermediary asks for the code or the push in real time. The exercise is technical: which control fails, not who “fell for an SMS”.
How we test the factor without breaking the IdP
We document which MFA the roles in the universe use: app, OTP, push, key. Without that map the scenario is generic and does not measure. IAM has to sit in the brief.
We build the proxy or challenge-capture flow without persisting secrets. The lure looks like the login people already use. The ethical cap is not reusing a real session and not touching IdP production.
We fire the lure at the agreed universe. We log who handed over the code, who approved the push and who stopped to verify on another channel. There is no mass marketing SMS blast.
The report turns the gesture into a control: fatigue, no matching, SMS OTP, no FIDO. Security and IAM get the same piece, in architecture language, not awareness-campaign language.
Why “we already have MFA” is an incomplete sentence
Because the second factor was designed for an attacker who is not in the session. The intermediary is: they see the challenge and pass it on. The OTP that travels by SMS or is read out loud is a one-time secret the proxy spends in the same…
What you get
Evidence of whether the second factor holds against an intermediary, written for IAM and for the program.
MFA map of the universe
Which factor each in-scope role uses. Without it the result cannot be read. It stays as an annex to the report.
Intermediary scenario
A controlled flow, no persisted secret, aligned to your IdP in appearance and not in production credentials.
Control report
Who handed over the factor and which control failed. A technical cut, not a “fell for phishing” rate.
Habit and architecture recommendation
What to ask of people (do not approve a blind push, do not read the OTP) and what to decide in IAM (matching, FIDO, out-of-band). Two lines, one owner each.
What we need from you
An IAM or identity counterpart who can explain the real second factor, not the one in the policy. Access to a lookalike environment — IdP branding, challenge copy — without… Also a universe of people who actually use MFA. A group still on password-only is useless. Exclusions: service accounts, break-glass, third parties. This service does not ask for…
How it fits the program
The 2FA attack does not replace email simulations or smishing. It is a measurement of the factor, not of the personal phone and not of an attachment click. It is read with IAM and with the index, in two different…
Often contracted alongside this one
Questions about 2FA attacks
Is this the same as credential phishing?
Do you touch our production IdP?
Does it work if MFA is a hardware key?
Is it an exercise for the whole roster?
Is there a price on the site?
Put the sentence “we have MFA” to the test
If the second factor was never measured against an intermediary, coverage is a hypothesis. Let’s talk with IAM.
Full catalog on Services