Executive summary

Enrolling your users in strong authenticators is only part of the journey toward achieving phishing resistance. That’s because a skilled social engineer on the phone to a targeted user isn’t deterred by the presence of a strong factor when phishing your user—they’re interested in abusing the weakest method that’s available in the targeted user’s account. Okta Threat Intelligence regularly observes attackers abusing this weakness by convincing a user to eschew a strong, phishing-resistant method of sign-in for one that can be phished. This technique, known as MFA downgrade, is something attackers are using regularly, so we're sharing some examples of what this looks like, how you can combat this threat, and why the time to act is now.

Social engineering is necessary because phishing-resistant authentication methods can’t authenticate targets to lookalike phishing domains. Therefore, attackers have found that an effective way around that is to trick targets into manually choosing a factor that is not phishing resistant. Luckily, organizations can protect against these MFA downgrade attempts by requiring users to only use phishing-resistant MFA factors and completely disabling the ability to switch to a less secure factor.

What is phishing-resistant authentication?

Let’s start with a refresher. A phishing-resistant method of authentication is one in which a cryptographic relationship is established between a user authenticator and the service provider during enrollment. What this means in plain language is that there is no shared secret for an attacker to intercept or trick a user into disclosing, which prevents the disclosure of sensitive authentication data to fake apps or websites. Even if an attacker knows a user's password, they cannot log in without physical access to that user's trusted device or security key.

Okta supports three types of phishing-resistant authentication methods: Okta FastPass, passkeys (following the FIDO2 WebAuthn standard), and Smart Cards (such as PIV cards). Many other factors are not phishing-resistant because they can be intercepted or approved by a deceived user; these include SMS, email, one-time passwords (OTPs), and even push requests with number matching. While these factors are useful in many cases, it’s important to remember they are not truly phishing resistant.

Threat analysis

Given that attackers can’t defeat true phishing-resistant authentication, they frequently use MFA downgrade techniques as part of “operator-in-the-loop” voice phishing attacks to trick users into using a phishable factor while they are live on the phone with the target. We have also observed MFA downgrade techniques in adversary-in-the-middle phishing attacks, in which attackers must convince the user to sign-in to a legitimate service via a transparent HTTP proxy. Attackers incorporate MFA downgrade pretexts into various parts of their campaign.

When the downgrade pretext is baked into the phishing kit

Starting in August 2026, Okta Threat Intelligence observed a phishing kit that steals the user’s credentials and one-time passcode, allowing the operator to manually log in before the code expires. Since attackers know that they can’t defeat phishing-resistant authentication, they attempt to convince the target to use a one-time passcode instead by giving them a fake reason that their hardware key is not working. The phishing kit displays the following message to the target in order to socially engineer them into downgrading their authentication from a Yubikey (a common phishing-resistant hardware key) to a passcode:

"If you currently utilize a Yubikey on your Okta, it may need to be re-registered."
Phishing kit lure attempting to convince users to downgrade MFA Phishing kit lure attempting to convince users to downgrade MFA

If the attacker successfully steals the target’s credentials and passcode, they take over the account. The attacker then persists by enrolling their own devices and soft tokens, deactivating existing MFA enrollments, and ultimately gaining unauthorized access to critical applications. (For additional details including indicators of compromise, Okta customers can access a detailed advisory here.)

When the downgrade pretext is in the lure

The social engineering attempt may not always be in the phishing kit, though. We observed downgrade pretexts in a campaign that abused instant messaging services in mid-2025. In this case, threat actors abused direct messages in Slack to direct users to phishing sites, instructing them to specifically avoid using Okta FastPass (given its protective and detective capabilities).

Slack message attempting to trick users into avoiding use of Okta FastPass Slack message attempting to trick users into avoiding use of Okta FastPass

Source: Phishing Campaigns target messaging services, Okta Threat Intelligence, August 2025

In another prior campaign from 2023, Okta’s security team observed a SMS-delivered phishing campaign in which targeted users were asked to remove their physical security key.

SMS message requesting targeted user to remove their physical security key. SMS message requesting targeted user to remove their physical security key.

Source: “An unexpected endorsement for WebAuthn”, Okta, July 2023

A targeted user that attempted to sign-in via the phishing site would likely use whatever remaining method of authentication was available in their account, often some combination of a password, OTP, or push notification.

Recommendations

Every time an attacker builds an MFA downgrade pretext into a lure or a kit, they are making a stronger case for enrolling users in phishing resistant methods of authentication like Okta FastPass or passkeys. The use of that pretext means that the attacker knows they will be defeated by phishing-resistant authentication. But clearly, enrollment isn’t enough. You can only prevent a skilled social engineer from achieving their objectives by denying them the ability to use weaker MFA factors to apps and data. It’s vital that organizations not only mandate enrollment in phishing-resistant authenticators, but also enforce the use of phishing-resistant authenticators for access to protected resources as well as to add or remove new factors.


The recommendations below are specific to the defense of Okta customers.

MITRE ATT&CK TechniqueControl Recommendation

T1566.004: Spearphishing Voice

T1684 Social Engineering

Enroll users in strong authenticators such as Okta FastPass, passkeys, or smart cards and enforce phishing resistance in policy.

Establish, communicate and evangelize methods of verifying the identity of helpdesk personnel when they contact users.

T1078 Valid Accounts

Deny requests from locations where your organization does not offer services. Okta network zones allow administrators to set policies that deny access to Okta-protected applications by geolocation (country), ASN, IP, or other criteria.

Okta authentication policies can be used to restrict access to user accounts based on a range of customer-configurable prerequisites. We recommend administrators restrict access to sensitive applications to devices that are managed by Endpoint Management tools and protected by endpoint security tools.

Notify users of every authenticator (factor) lifecycle event using end user notifications.

T1098.005 Account Manipulation: Device Registration

Apply Okta Account Management Policies that constrain the ability to add or modify authenticators based on network context, device management status, and enrolled authenticators.

Specific guidance is provided in this blog post.

This content is for informational purposes only, does not constitute professional advice, and is provided without warranties or liability; please consult your own advisors for implementation decisions.

Continue your Identity journey