Social Engineering Attacks Target MFA Enrollment and Recovery

Social Engineering Attacks Target MFA Enrollment and Recovery

First seen 4 Sep 2026, 15:18 UTC Infosecurity-Magazinewww.okta.com 64.5

Article Content

Browse articles
ThreatCluster

Over the past year, Okta Threat Intelligence has reported a rise in attacks where users are tricked into approving multi-factor authentication (MFA) enrollments and password resets initiated by attackers. These social engineering tactics have evolved, with attackers impersonating IT support to lure users into phishing traps. Recent campaigns have targeted passkey enrollment processes, exploiting the transition to phishing-resistant MFA. Okta noted that 20% of proactive notifications to customers in the last month were related to phishing domains containing 'passkey.' Microsoft also reported similar incidents where attackers bypassed authentication controls by manipulating self-service password reset processes. This trend highlights vulnerabilities in account recovery methods, which remain less secure than primary authentication. Organizations are urged to prioritize strengthening MFA enrollment and recovery processes to mitigate these risks.

Key Points: • Attacks increasingly target MFA enrollment and recovery processes. • Okta reported 20% of recent phishing notifications involved 'passkey' domains. • Attackers exploit weaknesses in self-service password resets and impersonate IT support.

Ask AI about this cluster

Timeline

2026-07-10
Okta reports rise in MFA-related attacks
Okta observed a growing number of attacks tricking users into approving MFA enrollments and password resets.
Okta
2026-09-04
Microsoft announces changes to Entra ID
Microsoft revealed that passkeys will become the default authentication method, deprecating SMS and voice options by year-end.
Infosecurity-Magazine
2026-09-04
Okta highlights social engineering tactics
Okta's research detailed how attackers are using social engineering to exploit account recovery and enrollment processes.
Okta