[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fGDZwlDs2gkp9wkxIV5JJP7XxTmTy_k7FWoGISQkVfhM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":43},"85fdeace-7109-496a-b3c6-273ff4c8c230","mfa-alone-fails-as-identity-based-attacks-drive-ransomware-surge","b841c6dc-2e82-4d33-8a81-0df155249eed","MFA Alone Fails as Identity-Based Attacks Drive Ransomware Surge","Attackers have shifted tactics, now prioritizing identity compromise over traditional software exploits, with email-based phishing and credential theft becoming the leading ransomware entry point. Critically, MFA was present in 97% of credential-based attack scenarios yet still failed to prevent breaches, indicating that poorly configured, bypassable, or phishing-susceptible MFA implementations are creating a false sense of security. This matters because organizations are over-relying on a single control — MFA — without layering defenses or addressing the human element that enables credential theft in the first place. A holistic identity security strategy combining phishing-resistant authentication, user education, and behavioral monitoring is now essential to closing this gap.","**Immediate Actions:**\n- Replace SMS\u002Femail-based MFA with phishing-resistant options such as FIDO2\u002Fpasskeys or hardware security keys for all privileged and remote access accounts.\n- Audit existing MFA configurations to identify and remediate bypass risks such as MFA fatigue settings, legacy authentication protocols, and conditional access gaps.\n\n**Long-term Improvements:**\n- Implement a Zero Trust identity architecture that enforces continuous verification, least-privilege access, and just-in-time provisioning for all users.\n- Deploy Identity Threat Detection and Response (ITDR) tooling to detect anomalous login behavior, impossible travel, and credential stuffing in real time.\n- Establish a regular security awareness training program focused specifically on phishing, social engineering, and credential hygiene.\n\n**Detection Measures:**\n- Enable comprehensive identity logging (sign-in logs, MFA prompts, token issuance) and forward to a SIEM for correlation and alerting.\n- Create automated alerts for high-risk authentication events such as new device logins, off-hours access, and multiple failed MFA attempts followed by success.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-63B – Digital Identity Guidelines (Authenticator Assurance Levels)","NIST AC-2 – Account Management","NIST AC-17 – Remote Access","NIST IA-5 – Authenticator Management","NIST IA-12 – Identity Proofing","MITRE ATT&CK T1078 – Valid Accounts","MITRE ATT&CK T1566 – Phishing","GDPR Article 32 – Security of Processing (appropriate technical measures)","published","2026-07-15T22:21:13.791499+00:00","2026-07-15T22:21:13.104+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.darkreading.com\u002Fidentity-access-management-security\u002Fidentity-attacks-overtake-exploits-top-ransomware-cause","identity-attacks-overtake-exploits-as-top-ransomware-cause-624a1c","Identity Attacks Overtake Exploits as Top Ransomware Cause",[31,37],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]