IT Myths Debunked, Part 1. Some myths haunt every security checklist. This one is still on yours, with a green checkmark next to it.
October is Cybersecurity Awareness Month, and multifactor authentication sits near the top of every checklist for good reason. Microsoft’s own numbers say phishing-resistant MFA stops more than 99% of identity attacks. The problem is the word “phishing-resistant,” which most businesses skip right past. Obsidian Security’s 2025 threat report found that MFA, the everyday kind, failed to prevent the attack in 84% of the incident responses it handled, and Proofpoint reported that 62% of organizations it monitored had at least one account taken over in 2024, with an average of twelve.
MFA is still worth having. The myth is that having it means the phishing problem is handled.
Myth 1: “We Have MFA, So We Cannot Be Phished”
This one persists because it used to be mostly true. Early phishing stole a password, and a second factor stopped the attacker cold. Attackers adjusted. The current playbook does not try to crack MFA; it lets the victim complete MFA and then steals the session that results.
- Adversary-in-the-middle phishing. The fake login page sits between the employee and the real one, passes the MFA prompt through, and keeps the authenticated session token.
- Device-code phishing. The employee is sent to a real Microsoft login page and told to enter a short code. They sign in, approve MFA, and the attacker walks away with the access token. Huntress recorded a 1,380% increase in these attacks in the first four months of 2026 compared to the back half of 2025, with no two lures identical, which points to AI generating them at scale.
- MFA fatigue. Push the approval prompt to someone’s phone often enough, at the wrong hour, and eventually a thumb hits “Approve” to make it stop.
None of these require cracking anything. They require an employee doing exactly what the login screen asks. The email that starts it all still has to land in an inbox first, which is where email security that catches the lure before anyone reads it earns its keep.
Myth 2: “A Strong Password Is the Real Protection”
Microsoft reports that more than 97% of identity attacks are password attacks, which sounds like an argument for stronger passwords until you look at how those attacks work. They are automated guessing runs using usernames and passwords leaked from other breaches. Length and complexity do not matter when the password itself is already in a dump from a site the employee signed up for in 2019 and reused at work. The fix is not a better password policy; it is a password manager generating one unique credential per account, so a leak somewhere else stays somewhere else.
Myth 3: “Passkeys Are a Consumer Thing”
Passkeys and hardware security keys are the phishing-resistant MFA in Microsoft’s 99% figure. They tie the login to the real domain, so a fake login page, a device-code trick, or a push prompt has nothing to grab. They are already built into Microsoft 365, Google Workspace, and most modern phones and laptops; the reason more Florida businesses have not turned them on is that nobody has told them the version they have now is the one attackers already know how to beat.
The Fix, In Three Steps
Basic MFA is the floor, not the ceiling. Text codes and push approvals were a good answer in 2019, and it is not 2019. What holds up now:
- Switch to phishing-resistant MFA. Turn on passkeys or hardware security keys for email, Microsoft 365 or Google Workspace, banking, and anything with customer data. They are tied to the real website, so a fake login page or an intercepted code has nothing to use.
- Put a password manager in front of every account. One unique password per login means a leak from some other site cannot be reused at work.
- Filter the email before anyone reads it. Every attack above starts with a message landing in an inbox. Stopping the lure is cheaper than stopping the login.
Do the first one this month if you do nothing else.
Where GiaSpace Fits
We move Florida businesses from the MFA they have to the MFA that still works, without turning login into an obstacle course for staff.
→ Schedule a Security Review with Rob Giannini, our CEO & Founder



