<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.itpro.com/uk/feeds/tag/two-factor-authentication-2fa"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from ITPro UK in Two-factor-authentication-2fa ]]></title>
                <link>https://www.itpro.com/uk/tag/two-factor-authentication</link>
        <description><![CDATA[ All the latest two-factor-authentication-2fa content from the ITPro  UK team ]]></description>
                                    <lastBuildDate>Thu, 05 Mar 2026 11:52:32 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Law enforcement and security firms take down huge PhaaS platform ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/law-enforcement-and-security-firms-take-down-huge-phaas-platform</link>
                                                                            <description>
                            <![CDATA[ Tycoon 2FA has been responsible for tens of millions of phishing messages, reaching over 500,000 organizations each month worldwide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tNhGfU3M78qDnNEoakTNaA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HoZtCmwBXTjKRszdxC2LML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 05 Mar 2026 11:52:32 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HoZtCmwBXTjKRszdxC2LML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image of 2FA showing a man on a laptop using phone to authenticate login details.]]></media:description>                                                            <media:text><![CDATA[Concept image of 2FA showing a man on a laptop using phone to authenticate login details.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image of 2FA showing a man on a laptop using phone to authenticate login details.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HoZtCmwBXTjKRszdxC2LML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft, Europol, and several security firms have teamed up to disrupt the Tycoon 2FA <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing-as-a-service (PhaaS)</a> platform.</p><p>First spotted in August 2023, Tycoon 2FA uses <a href="https://www.itpro.com/security/cyber-crime/adversary-in-the-middle-attacks-are-becoming-hackers-go-to-method-to-bypass-mfa">adversary-in-the-middle (AitM)</a> proxying to bypass traditional <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">multi-factor authentication (MFA)</a> and capture session cookies in real time, leading to large-scale account compromise. </p><p>It proxies the real <a href="https://www.itpro.com/desktop-software/19337/office-365-review">Microsoft 365</a> or Google login page, and when the victim enters their credentials and MFA code, passes them to the legitimate service in real-time.</p><p>And once the service says "Identity Confirmed", it sends back a session token – which is grabbed by Tycoon 2FA before it ever reaches the victim's browser, and incorporated into the attacker's own browser. Since the session is already "authenticated," the platform never asks the user for a code.</p><p>Thanks to its complete PhaaS ecosystem, Tycoon 2FA lowered the barriers to entry for cyber criminals. It offered convincing phishing templates, realistic landing pages, and real‑time capture of credentials and authentication codes, all incorporated into an easy‑to‑use package that scaled quickly. Phishing kits started at just $120 for 10 days' access and $350 for a month.</p><p>Campaigns frequently extended beyond simple account access into <a href="https://www.itpro.com/security/cyber-attacks/what-is-business-email-compromise-bec">Business Email Compromise</a> (BEC) attacks. By leveraging hijacked session tokens, attackers were able to embed themselves within corporate email environments to monitor internal communications and financial workflows. </p><p>From here, they could send legitimate-looking invoices from the compromised account to a third-party partner or vendor. </p><p>"Because the fraudulent request originated from a trusted, authenticated account, this multi-stage fraud model bypassed traditional email security filters," Cloudflare wrote in a <a href="https://www.cloudflare.com/en-gb/threat-intelligence/research/report/tycoon-2fa-takedown/">blog post</a>. </p><p>"This allowed attackers to successfully divert payments to criminal-controlled mule accounts, resulting in significant financial losses." </p><p>The group has been responsible for tens of millions of phishing messages reaching over 500,000 organizations each month worldwide. It's been linked to more than 96,000 distinct phishing victims globally, including more than 55,000 Microsoft customers and around 5,350 distinct phishing victims in the UK. </p><p>It's hit sectors including education, healthcare, finance, non-profit, and government. By the middle of last year, <a href="https://www.itpro.com/security/tycoon-2fa-the-popular-phishing-kit-built-to-bypass-microsoft-and-gmail-2fa-security-protections-just-got-a-major-upgrade-and-its-now-even-harder-to-detect">Tycoon 2FA</a> accounted for around 62% of all phishing attempts blocked by Microsoft.</p><p>Now, though, in action coordinated by Europol's European Cybercrime Centre (EC3), Microsoft has seized 330 domains forming the core infrastructure of the criminal service, including phishing pages and control panels. </p><p>"Disrupting Tycoon 2FA spanned multiple jurisdictions, underscoring why sustained, coordinated pressure is essential, especially as cybercrime becomes more scalable through automation and AI," said Steven Masada, assistant general counsel in Microsoft's Digital Crimes Unit. </p><p>However, warned Trend Micro, taking down the platform is by no means the end of the job. </p><p>"Operators have always been known to adapt, rebuild, and migrate to new infrastructure," said the firm in its <a href="https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html">blog</a>. "Known and suspected users of Tycoon 2FA can attempt to continue operations, and previously stolen credentials and session cookies remain in circulation."</p><p>The participants in the takedown operation said they plan to monitor for signs of the service resurfacing, and investigate the users and administrators they've been able to identify so far.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitHub launches passkeys beta for passwordless authentication ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/github-launches-passkeys-beta-for-passwordless-authentication</link>
                                                                            <description>
                            <![CDATA[ Users can now opt-in to using passkeys, replacing their password and 2FA method ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5Kr2aNVKiLVdMj9noMzVDf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Jul 2023 15:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Jul 2023 14:06:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:description>                                                            <media:text><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:text>
                                <media:title type="plain"><![CDATA[GitHub logo on a smartphone placed down on a desk next to a green notepad and pink pen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ga5RPZLpRRrQk37pK25UzE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>GitHub has announced the arrival of its passkeys public beta for passwordless authentication, which the company says will enable seamless and secure access on GitHub.com.</p><p>The move will allow users to upgrade their security keys to passkeys to be used in place of both passwords and two-factor authentication (2FA) to bolster overall account security.</p><p>In an announcement, the firm explained that most security breaches involve lower-cost attacks such as social engineering, credential theft, or leakage. </p><p>According to data from the FIDO Alliance, the team behind the global authentication standard based on <a href="https://www.itpro.com/security/31775/what-is-public-key-infrastructure-pki"><u>public key cryptography</u></a>, passwords are estimated to be the root cause of over 80% of data breaches globally.</p><p>To tackle this, GitHub said its new passkeys bring easier configuration and enhanced recoverability, providing a secure and private way to protect accounts and minimize the risk of lockouts.</p><p>“GitHub is committed to helping all developers employ strong account security while staying true to our promise of not compromising their user experience,” said Hirsch Singhal, staff product manager at GitHub. “We began this commitment with our <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication"><u>2FA</u></a> initiative across GitHub. </p><p>“Today, we are furthering this work by ensuring seamless and secure access on GitHub.com with the public beta of passkey authentication.”</p><p>Users can implement passkeys via the ‘Feature Preview’ tab in the settings sidebar, which now displays an option to ‘enable passkeys’. This will enable the option to upgrade eligible security keys to passkeys, as well as register new passkeys.</p><h2 id="how-github-passkeys-work">How GitHub passkeys work</h2><p>The new passkeys essentially count as two security layers in one, combining a <a href="https://www.itpro.com/security/29705/what-are-biometrics"><u>user element such as a thumbprint</u></a>, face, or knowledge of a PIN, with a physical element such as a security key or device.</p><p>Due to expanded browser support, GitHub said a browser’s autofill system can automatically suggest that users use their passkey to sign in straight from the login page – regardless of whether a user has 2FA enabled.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED RESOURCE</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="2nNdcPL9CGTu8jwiuvm3GK" name="State of Email Security 2023_thumb.jpg" caption="" alt="Black whitepaper cover with strapline and image of man's face overlaid looking in different directions" src="https://cdn.mos.cms.futurecdn.net/2nNdcPL9CGTu8jwiuvm3GK.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Mimecast)</span></figcaption></figure><p class="fancy-box__body-text"><strong>The state of email security 2023</strong></p><p class="fancy-box__body-text">Discover how leaders are protecting their organizations from cyber attacks in the face of increases in email usage. </p><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/security/phishing/the-state-of-email-security-2023">DOWNLOAD FOR FREE</a></p></div></div><p>Passkeys can also be used across more than just the device they were created on, thanks to a new experience labeled ‘Cross-Device Authentication’. </p><p>This allows the use of a passkey on a phone to sign into a laptop, for example, by verifying the phone’s presence.</p><p>“Because your phone or tablet must be physically close to your laptop or desktop, Cross-Device Authentication retains the phishing-resistant promise of FIDO,” Singhal said.</p><p>Additionally, many passkeys can be synced across multiple devices to help prevent account lock-out due to key loss. This can be done automatically, depending on passkey provider, GitHub said. </p><h2 id="how-to-upgrade">How to upgrade</h2><p>Existing user security keys that are capable of verifying identity – such as Touch ID, Windows Hello, Android thumbprints, or PIN-locked or biometric hardware keys – are eligible to be upgraded.</p><p>Upon next sign in with the security key, GitHub will ask users if they would like to upgrade to a passkey. This will then re-register the security key with the user’s <a href="https://www.itpro.com/security/phishing/as-google-launches-passwordless-authentication-for-all-what-are-the-business-benefits-of-passkeys"><u>passkey</u></a> provider to ensure it is discoverable during authentication and synced. Up-to-date devices support passkeys straight out of the box.</p><p>“Because passkeys are privacy-preserving, you might have to trigger your passkey a few times during that upgrade flow so we can make sure we’re upgrading the right credential,” Singhal said. “Once you do, you’re all set for a <a href="https://www.itpro.com/security/information-security-infosec/369242/sooner-fido-can-shut-down-passwords-the-better"><u>passwordless experience</u></a>.</p><p>“By registering durable, secure credentials across all your devices, we hope to prevent account lockouts due to device loss,” Singhal added. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is two-factor authentication? ]]></title>
                                                                                                                                                                                                <link>https://www.itpro.com/security/29982/what-is-two-factor-authentication</link>
                                                                            <description>
                            <![CDATA[ Passwords aren't secure; it's time to add multi-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gQvfHS4mVm2Use6tZBEpjC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 26 Jun 2018 11:26:10 +0000</pubDate>                                                                                                                                <updated>Fri, 06 Sep 2024 15:27:50 +0000</updated>
                                                                                                                                            <category><![CDATA[Hacking]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Nicholas Fearn ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:description>                                                            <media:text><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration of a laptop with a lock screen overlaid with a phone showing a tick symbol, to represent two-factor authentication (2FA) and multi-factor authentication (MFA). Decorative: the illustration is entirely rendered in black and white.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Wdn8Yytj7fHsU8qTd49YVh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cybercrime is arguably the biggest threat affecting modern businesses. Half of British companies have experienced a cybersecurity incident over the past year, with large (74%) and medium (70%) firms being the most affected. </p><p>That’s according to the<a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2024/cyber-security-breaches-survey-2024#:~:text=Half%20of%20businesses%20(50%25),in%20annual%20income%20(66%25)." target="_blank"><u> 2024 Cyber Security Breaches Survey</u></a> from the UK Government, which also found that <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a> attacks, email and online impersonation, and malware are the biggest cybersecurity threats faced by UK firms.</p><p>Two-factor authentication (2FA) adds an extra barrier of entry for any third party attempting to access your account.</p><p>Requiring users to complete a second round of authentication after entering a password, whether by entering a code sent via text message or email or by using an authenticator app, adds a far more robust protective layer. While it may seem arduous to jump through these hoops, the benefits of having them in place are untold.</p><h2 class="article-body__section" id="section-what-is-the-difference-between-2fa-and-mfa"><span>What is the difference between 2FA and MFA?</span></h2><p>Two-factor authentication (2FA) is a form of multi-factor authentication (MFA) designed to add an additional layer of security to online accounts, services, and apps. It requires users to prove their identity using two forms of authentication, the first of which is a combination of a username and a password. </p><p><a href="https://www.itpro.com/security/34616/the-top-password-cracking-techniques-used-by-hackers">Passwords are often stolen by hackers</a> and 2FA aims to solve this by forcing anyone attempting to access an online account or service to confirm their identity via a second form of authentication. </p><p>Common examples include one-time passwords, push notifications, <a href="https://www.itpro.com/security/29705/what-are-biometrics">biometrics</a>, physical security keys, or codes generated by authentication apps. The premise is that only users will know or have access to this information, preventing unauthorized parties from accessing their accounts using breaches or <a href="https://www.itpro.com/security/data-breaches/a-treasure-trove-for-adversaries-10-billion-stolen-passwords-have-been-shared-online-in-the-biggest-data-leak-of-all-time">leaked passwords</a>. </p><p>Although 2FA falls under the MFA umbrella, it wouldn’t be accurate to use the former to describe the latter. The main difference between the two is that while 2FA only uses two forms of authentication, MFA relies on two or more methods for verifying user identities.</p><p>For instance, a user with MFA set up on their account could be asked to first complete a one-time password request after logging in with their username and password, then an additional form of authentication like a fingerprint. Only after passing these stages would they be able to access their account. </p><h2 class="article-body__section" id="section-how-does-two-factor-authentication-work"><span>How does two-factor authentication work?</span></h2><p>Two-factor authentication invariably uses a second, independent device that functions as a buffer between the service and the login attempt.</p><p>Some services will supply their own keys, although this has become less common as companies have turned to developing their own smartphone apps or making use of SMS messages. Regardless of whether it's a number-generating key or a confirmation message, the idea is that only the owner of the device will have access to the key and the ability to authorize the login attempt.</p><p>The additional security check normally appears after the user has submitted their username and password. Once the system checks that the account exists, it will then ask the user to perform an additional action.</p><p>Two-factor authentication has become ubiquitous with most online services that involve sensitive data, whether it’s banking or financial services, e-commerce, or <a href="https://www.itpro.com/security/two-factor-authentication-2fa/357071/zoom-rolls-out-two-factor-authentication">business applications</a> – although many other companies are starting to offer 2FA to stand out from the competition.</p><p>How that additional layer appears can vary from service to service. For example, most banks now have their own security tokens for online banking, often in the form of random number generators and usually offered through a smartphone application, although some users may still be using a physical fob. Many online services have now forced users to set up 2FA as a minimum, <a href="https://www.itpro.com/security/359443/googles-about-to-push-everyone-into-two-factor-authentication">including Google</a> and <a href="https://www.itpro.com/security/two-factor-authentication-2fa/361731/meta-makes-2fa-mandatory-for-high-risk-users">Meta</a> though the latter only has this requirement for 'high risk' accounts.</p><p>Getting through a second layer of security can be the slowest part of signing into a service but it's an effective way of sifting out those trying to brute force their way into an account.</p><h2 class="article-body__section" id="section-what-are-the-benefits-of-2fa"><span>What are the benefits of 2FA?</span></h2><p>The biggest benefit of 2FA is preventing cyber criminals from breaching online accounts using passwords they've stolen or found in leaked databases on the <a href="https://www.itpro.com/security/32117/what-is-the-dark-web">dark web</a>. But there are other reasons why you should use this security feature. </p><p>2FA can help tackle password fatigue, the feelings of tiredness associated with having to constantly remember and enter myriad passwords. It means you can choose an easy-to-remember password with the peace of mind that your account will be secured by a second authentication method.</p><p>Security leaders have less cause to worry about account breaches if they have a good 2FA policy in place, in the knowledge that cybercriminals have that extra barrier to entry. Adopting features like 2FA is also key to developing a <a href="https://www.itpro.com/security/encouraging-a-security-first-mindset">security-first mindset</a> — paramount as the <a href="https://www.itpro.com/security/world-economic-forum-warns-of-growing-cyber-insecurity-amid-heightened-threat-landscape">threat landscape worsens</a>. </p><p><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches">Remote workers are still difficult for security teams</a><a href="https://www.itpro.com/security/why-remote-work-is-still-giving-cisos-security-headaches"></a> to support, as their devices and corporate access need to be properly configured with 2FA or MFA, but this step is essential for protecting critical corporate accounts while supporting a <a href="https://www.itpro.com/business-strategy/flexible-working/370225/lessons-of-covid-19-shaping-the-future-of-hybrid-work">hybrid work model</a>. This is particularly critical for offices that take a <a href="https://www.itpro.com/business/business-strategy/the-top-4-byod-risks-businesses-face">bring your own device (BYOD)</a> approach, as home devices can be more vulnerable to password-stealing malware and therefore need the extra line of defense.</p><p>Using 2FA methods like passkeys and authenticator apps provides users with “better and more secure protection”, says ESET global cybersecurity advisor Jake Moore.</p><p>“When threats are multi-layered themselves, accounts need the strongest multi-layered protection to stay secure,” he tells <em>ITPro</em>.</p><p>But as well as protecting against password breaches, 2FA could also bring about a <a href="https://www.itpro.com/security/the-end-of-passwords-and-how-businesses-will-embrace-it">passwordless future</a>. Moore says this is possible thanks to “superior security options” that offer greater pxrotection against phishing and brute-force attacks than single passwords. He adds:  “Passkeys, for example, offer ease of use, security as well as convenience and are already being rolled out smoothly across multiple accounts.”</p><iframe allow="" height="200px" width="100%" data-lazy-priority="high" data-lazy-src="https://widget.spreaker.com/player?episode_id=52362789&theme=light&playlist=false&playlist-continuous=false&chapters-image=true&episode_image_position=right&hide-logo=false&hide-likes=true&hide-comments=true&hide-sharing=true&hide-download=true"></iframe><h2 class="article-body__section" id="section-is-two-factor-authentication-safe"><span>Is two-factor authentication safe?</span></h2><p>Despite the benefits it offers, it's worth noting that <a href="https://www.itpro.com/security/cyber-attacks/354868/android-cerberus-malware-can-hack-google-authenticator">multi-factor authentication is not 100% secure</a>. Microsoft has warned businesses against using systems that rely on voice and SMS due to security concerns, warning that these methods use no <a href="https://www.itpro.com/security/innovation-at-work/24460/what-is-data-encryption">encryption</a> and are therefore ripe for interception by hackers. With private details to hand, hackers can launch <a href="https://www.itpro.com/social-engineering/30017/social-engineering-the-biggest-security-risk-to-your-business" target="_blank">social engineering</a> campaigns </p><p>For example, authentication via text message is vulnerable to interception and spoofing by hackers, particularly if they can hijack an account that supports a person's mobile number. Various account recovery processes for lost passwords can also be harnessed by hackers to work around two-factor authentication. </p><p>Sophisticated <a href="https://www.itpro.com/malware/28076/what-is-malware" target="_blank">malware</a> that has infected computers and mobile devices <a href="https://www.itpro.com/security/tycoon-2fa-the-popular-phishing-kit-built-to-bypass-microsoft-and-gmail-2fa-security-protections-just-got-a-major-upgrade-and-its-now-even-harder-to-detect">can redirect authentication messages</a> and prompts to a device belonging to a hacker, rather than the legitimate account holder, thereby working within but also around two-factor authentication.</p><div  class="fancy-box"><div class="fancy_box-title">RELATED WHITEPAPER</div><div class="fancy_box_body"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="G4z9HRkWymxjNBTJAFRrxj" name="BCDR buyers guide_listing.jpg" caption="" alt="BCDR buyer's guide for MSPs whitepaper from Datto" src="https://cdn.mos.cms.futurecdn.net/G4z9HRkWymxjNBTJAFRrxj.jpg" mos="" link="" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pinterest-pin-exclude"></p></div></div><figcaption itemprop="caption description" class=""><span class="credit" itemprop="copyrightHolder">(Image credit: Datto)</span></figcaption></figure><p class="fancy-box__body-text"><a data-analytics-id="inline-link" href="https://www.itpro.com/business-operations/managed-service-provider-msp/359139/bcdr-buyers-guide-for-msps">Dispels misconceptions about BCDR solutions</a></p></div></div><p>The most secure methods of 2FA use dedicated hardware tokens, such as a <a href="https://www.itpro.com/cloud/cloud-security/354809/google-expands-usb-c-titan-security-keys-to-10-countries" target="_blank">Google Titan Security Key</a> or YubiKey, which are difficult for hackers to spoof unless they physically steal one. Google's offering, for example, uses cryptography to verify a user's identity and a separate URL to stop would-be attackers from accessing accounts even if they have the username and password. </p><p>Methods of 2FA reliant on codes sent via SMS are best avoided if you are running an enterprise with a treasure trove of data. This is because SMS is vulnerable to <a href="https://www.itpro.com/security/cyber-attacks/cisa-urges-organizations-to-adopt-passwordless-security-in-lapsusdollar-report">SIM swap attacks</a>, in which attackers transfer a victim's number to a SIM card in their possession to intercept their messages. If they pull this off on a user they know uses SMS-based 2FA, they could gain access to their account without any alarms going off.</p><p>While 2FA may not be quite the security silver bullet it was once expected to be, it's still an important area of security and access control to keep in mind when procuring and setting up services for your business or personal life, because the more hurdles you can put in the hackers' way, the less likely they are to target you.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>