← All posts

MFA and Email Security: What Actually Stops BEC in 2026

September 16, 2026

Not all multi-factor authentication resists modern phishing. Here is the difference between MFA that stops account takeover and MFA that only slows it down.

"We have MFA" is no longer an answer to business email compromise. The question is which factor, and against which attack.

The attack that changed the math

Adversary-in-the-middle phishing proxies the real login page. The victim enters their password on a convincing replica, completes the genuine MFA prompt, and the attacker captures the resulting session cookie. No second factor is bypassed — it is satisfied, and then the session is stolen. Phishing kits sold as a service do this by default now.

How the factors rank

  • SMS codes. Weakest. Phishable, and vulnerable to SIM swapping.
  • App-generated codes (TOTP). Better, still phishable via proxy.
  • Push approval. Convenient, defeated by proxying and by fatigue attacks. Number matching helps against fatigue, not against session theft.
  • Passkeys and FIDO2 security keys. Phishing-resistant. The credential is bound to the real origin, so a proxy page cannot use it.
  • Certificate-based authentication with device compliance. Strong in managed fleets.

What to do with that

Start where loss concentrates: finance, accounts payable, executives, and administrators. Move them to passkeys or hardware keys first. Then extend by risk rather than trying to convert everyone at once.

MFA is necessary but not sufficient

Even with strong factors, add:

  • Token lifetime and session controls, so a stolen session expires quickly
  • Device compliance requirements for mail access
  • Alerting on new MFA registrations, a classic persistence step
  • Out-of-band payment verification, which stops the loss regardless of authentication

The uncomfortable truth is that a company with SMS-based MFA and no payment verification process is more exposed than one with weak MFA and a strict callback rule. Both is better. Our strategy and consulting team sequences this work so the highest-risk accounts move first.


Business email compromised right now? Call 1-844-LYRA-REC — our incident commanders answer live 24/7 and start containment on the first call. See our business email compromise response page for the first-hour checklist.

MFAphishing-resistantpasskeysemail security

24 / 7 Recovery

When the worst day hits, every minute matters.

Our breach team is standing by — call, email, or submit a request and we respond within minutes.