WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Cyber Hygiene – Phishing Resistant MFA and Complex Passwords
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Cyber Hygiene – Phishing Resistant MFA and Complex Passwords

Author: Alec Davison

Created: Tuesday, May 2, 2023 - 18:22

Categories: Cybersecurity, Security Preparedness

Despite all the hype, many organizations implementing multifactor authentication (MFA) and complex passwords can still fall victim to cyber attacks. Multiple threat actor types are increasingly bypassing MFA controls, typically through MFA push notification fatigue or exploiting weaknesses in self-enrollment configurations, to gain access to a victim’s network. In fact, past compromises impacting Okta, Twilio, Cloudflare, and Cisco highlight the determination and success threat actors are exhibiting at gaining valid credentials, including accounts with MFA controls. Consequently, MFA solutions using text-based one-time passwords are the least secure and can be bypassed. More secure forms of MFA include, but are not limited to, hardware-based USB security keys, biometric security, or smart cards. Additionally, while employees may have adopted passwords with special characters and increasing length, often they surround a word with numbers and special characters that can be trivially cracked within minutes. To overcome this threat, it’s recommended to not enforce regular password changes, focus on overall password length versus complexity, and screen passwords against commonly used dictionary words. Read more about Phishing Resistant MFA at HelpNetSecuirty or read more about complex passwords at BleepingComputer.

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar