IdentitySecurityMFA 5 min read

Why Your Current MFA Really Isn't MFA

Tony Rajakumar, Founder, Vercrio

Tony Rajakumar

Founder, Vercrio

A hard truth for CISOs: the "multi" in your multi-factor authentication may be an illusion.

Interlocking chain links with one made of paper
Your identity chain is only as strong as its weakest link

If you're a CISO, you've almost certainly checked the "MFA deployed" box on your compliance scorecard. Your organization rolled out Duo, Okta Verify, Microsoft Authenticator, or Ping years ago. Auditors are satisfied. The board is reassured. And yet — attackers keep walking right through the front door.

How? Because the MFA you're relying on isn't truly multi-factor in the way the standards bodies intended.

What the Standards Say

Every major authoritative source on authentication — NIST, PCI SSC, OWASP — agrees on a foundational principle: the factors in multi-factor authentication must be independent.

NIST SP 800-63B makes it explicit: authenticator assurance levels depend on combining factors whose compromise is uncorrelated. The PCI Security Standards Council is even more pointed in its *Multi-Factor Authentication Guidance*:

"The authentication mechanisms used for MFA should be independent of one another such that access to one factor does not grant access to any other factor, and the compromise of any one factor does not affect the integrity or confidentiality of any other factor."

OWASP echoes this in its *Multifactor Authentication Cheat Sheet*:

"Requiring multiple instances of the same authentication factor... does not constitute MFA and offers minimal additional security. The factors used should be independent of each other and should not be able to be compromised by the same attack."

The logic is airtight. If two factors fall to the same attack, you don't have two factors.

The Hidden Dependency Nobody Talks About

The logic breaks at the weakest link in the identity chain - the identity proofing that precedes those factor assignments. All those multiple factors were assigned based on one easily stolen factor type.

In nearly every organization, the process to assign the dependent factors is the same. An employee calls the helpdesk when:

They forgot their password.They bought a new phone and need their authenticator app re-provisioned.They're being onboarded for the first time.

The helpdesk agent runs an identity proofing process — almost always based on knowledge-based verification: date of birth, employee ID, manager's name, last four of the SSN, maybe a security question or two. Once the agent is satisfied, the user is handed a new password or their authenticator app is activated on a new device.

Both of your supposedly independent factors — the password and the device-based token — were just issued on the back of a single factor - knowledge-based verification.

It doesn't matter how many knowledge-based questions the agent asked. Per NIST and OWASP, they all collapse into one factor: something you know. And if an attacker compromises that one factor, they get handed both of your "independent" authentication factors on a silver platter, as multiple enterprises are finding out to their detriment.

Why This Matters Now More Than Ever

The knowledge-based questions that gatekeep your entire identity perimeter are no longer secret. After decades of breaches, that data sits on dark web marketplaces priced in the low double digits of dollars. A motivated attacker with a few hundred dollars in Bitcoin can assemble a full dossier on any targeted employee.

Add SIM-swapping to the mix — an industrialized service available for a flat fee — and the "phone number on file" defense evaporates. Attackers don't need to break your cryptography. They just call your helpdesk, answer the questions, and request that the authenticator app be migrated to the phone they now control.

This is exactly the playbook behind the MGM Casinos attack ($100M in losses), the Scattered Spider campaigns, the Coinbase insider bribery incident, and Lapsus$. None of these attacks defeated MFA technology. They defeated the identity proofing process that issued the factors.

As George Kurtz of CrowdStrike famously put it: "Adversaries don't break in. They log in."

George Kurtz: Adversaries don't break in. They log in.
George Kurtz: Adversaries don't break in. They log in.

The data backs him up. Cyentia Institute's *Information Risk Insights Study 2022*, drawing on 77,000 cyber incidents and $57 billion in losses, found that:

"Phishing and valid accounts rank among the top three techniques for most industries. If you want to keep threat actors out of your systems (and who doesn't?), prioritizing detections and defenses for those vectors should be very high on your list."

Valid accounts — the technical term for "logging in with legitimately-issued credentials" — is the #1 initial access technique in most sectors. The attack vector is the MFA system itself, weakened by a proofing process that pretends to be secure.

It Gets Worse: The Insider Threat

Attackers have now figured out that they don't even have to use stolen information - they can simply pay off your low-paid helpdesk agent and help themselves to their desired credentials. See Ransomware Flows In Through The Holes In Your Helpdesk. So your one factor identity proofing now collapses to zero factors backing up your identity issuance. The Coinbase attack demonstrated the provably insecure nature of the identity proofing process at most enterprises.

Breaking the Dependency with PeerProofing™

This is precisely the problem Vercrio's patented PeerProofing was designed to eliminate. Instead of anchoring trust with an agent at the helpdesk, PeerProofing anchors it in something attackers cannot buy on the dark web: the trusted relationships your employees already have with their teammates.

Here's how it works:

1. The user records a short selfie-video on the Vercrio app, stating their name.2. Vercrio's algorithm automatically selects a random set of the user's actual peers — colleagues who know what they look and sound like every day.3. Those peers receive the video on their own Vercrio app. If they recognize their colleague, they approve. If any peer rejects, the process stops instantly.

The helpdesk is removed from the identity proofing loop entirely. There are no knowledge-based questions to steal. There is no single agent to social-engineer or bribe. There is no SIM-swap to exploit. The random selection of peers means attackers can't pre-compromise an insider, because they don't know in advance who will be chosen. And because the selfie video is collected live through the app, the process is engineered to resist deepfake attacks — videos can be screened for synthetic artifacts before being presented to peers.

PeerProofing In Action
PeerProofing in action.

Real MFA, Built on a Real Foundation

Once PeerProofing completes, Vercrio's LucidAuth™ derives two genuinely independent authentication factors:

Something you have: The phone on which the peer-verified video was captured. Vercrio has high confidence this device is bound to the true user because their peers just said so.Something you are: Biometrics derived from the peer-verified video, stored securely on the device itself.

PeerProofing is the world's first mobile-delivered provably secure proofing process. Combining PeerProofing's provably secure proofing with LucidAuth's zero-password multifactor authentication yields an entirely new cybersecurity category: Ultrasecure Frictionless Authentication (UFA).

And as a bonus? Every subsequent login uses these two factors directly. Passwords disappear entirely. The helpdesk is no longer tied up resetting them or re-provisioning authenticator apps — cost savings that drop straight to the bottom line.

Because UFA delivers identity confidence combined with zero-password authentication, entirely new applications are possible to optimize operational efficiencies.

The CISO's Takeaway

The MFA deployment you've been relying on isn't protecting you. Its factors are only nominally independent, resting on a helpdesk identity proofing process that attackers have already industrialized a playbook against. PeerProofing delivers what your current identity process is missing - foundational identity confidence that can back up multiple authentication factors.

Try for free