WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Cyber Resilience – MFA is not a Substitute for Employee Training
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Cyber Resilience – MFA is not a Substitute for Employee Training

Author: April Zupan

Created: Tuesday, February 14, 2023 - 20:19

Categories: Cybersecurity

Dark Reading has written an article about the recent reddit hack and how the details that have been released demonstrate the limitations of two-factor authentication and the benefits of employee training. Despite reddit requiring the use of two-factor authentication internally, attackers were still able to convince an employee to click on a malicious link and harvest their credentials. As WaterISAC has reported previously, as more organizations move to two-factor authentication, more methods to bypass its most common implementations are being discovered by threat actors. However, this breach also demonstrated the value of employee training, as the reddit employee quickly grew suspicious after entering their credentials into the phishing site. They knew to contact IT promptly, which significantly reduced the duration the attackers had uncontested access to the network. Read more at Dark Reading.

Prior WaterISAC reporting on MFA Bypass

  • MFA is Being Bypassed with More Fervor
  • A Tale of Two (More) Attacks – How MFA Saved the Day for Cloudflare and Not So Much for Cisco
  • What the Twilio Breach Teaches Us About Smishing and Access to Corporate Accounts and Data

Related Resources

(TLP:CLEAR) FIRESTARTER Backdoor and Updated Emergency Directive for CISCO Firepower and Secure Firewall Devices

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:GREEN) FBI FLASH – Newly Observed Ransomware Variant Black Shrantac Threat to U.S. Entities

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Likely PRC State-Sponsored Activity Observed in the Water Sector – DocuSign Phishing Tactics Identified

Apr 23, 2026 in Cybersecurity, Federal & State Resources, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar