CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Only 28% of financial workforce MFA is phishing-resistant

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2306

As cited

Copy frozen at (site build).

identity access

Only 28% of financial workforce MFA is phishing-resistant

A Secret Double Octopus report found that only 28% of multifactor authentication (MFA) deployments in financial organizations use phishing-resistant methods, with most relying on passwords combined with one-time passwords (OTP) that remain vulnerable to credential theft and phishing attacks. Financial institutions continue to mix legacy authentication approaches with more secure technologies, leaving significant portions of their workforce exposed to identity-based threats.

Why it matters: Financial services practitioners need to accelerate migration to phishing-resistant MFA (such as FIDO2) across their workforce, as the majority still depend on vulnerable password-plus-OTP combinations that create actionable targets for attackers seeking account compromise and lateral movement.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary