Multi-factor authentication stops more than 99.2% of account compromise attacks, according to Microsoft - but it does not stop phishing. Attackers adapted years ago: they phish the second factor now, not just the password. MFA and security awareness training are not competing controls; they cover each other's blind spots, and this article shows exactly where each one fails so you can see why you need both.
TL;DR
- Microsoft's research says MFA blocks over 99.2% of account compromise attacks - it remains the single highest-value account control.
- MFA does not stop phishing: real-time reverse proxies, MFA fatigue prompts and SIM swaps defeat it, and stolen session cookies bypass it entirely.
- Verizon's 2025 DBIR found the human element in about 60% of breaches, and noted that click rates in their own research were unaffected by training alone - which is why simulations and reporting culture matter alongside training.
- The pairing that works: security awareness training plus phishing simulations on the people side, MFA everywhere on the account side.
Why this matters
Many small businesses treat MFA as the finish line: once it is on, they think phishing no longer matters. That belief is expensive. If phishing were solved by MFA, credential phishing would not remain the most common initial access vector in breach data - yet Verizon's 2025 DBIR still ranks credential abuse at the top, with the human element involved in roughly 60% of breaches. MFA changes what a phisher has to steal, not whether they try.
What MFA genuinely protects
MFA means a second proof - an app prompt, a code, a security key - on top of the password. Its headline number is real: Microsoft's own research states MFA can block more than 99.2% of account compromise attacks. For bulk attacks - criminals spraying stolen password lists across thousands of accounts - MFA is close to a wall. Every Australian business should turn it on everywhere it is offered: email, accounting, myGov (which now supports passkeys), banking and the company's own systems.
Where MFA fails against phishing
Attackers did not give up when MFA arrived; they moved up a step. Four techniques beat most standard MFA:
- Real-time reverse proxies (AiTM). The victim clicks a convincing login link, the attacker's proxy site relays the real login page, MFA succeeds - and the attacker grabs the session cookie. They never needed your password; they ride the session MFA just approved. Microsoft and the ACSC have both documented this technique against Microsoft 365 tenants.
- MFA fatigue and prompt bombing. The attacker already has the password (often from an earlier breach) and spams approval prompts at 2am until someone taps 'approve' to make it stop.
- SIM swap and voice redirects. Where the second factor is an SMS code, attackers port the phone number to their own SIM and receive your codes.
- The consent screen. OAuth phishing asks the user to approve a malicious app with their work account - MFA succeeds legitimately, and the app keeps access without ever needing the password.
The common thread: every one of these requires a human to click, approve, or read out a code. That is the phishing attack surface, and no account setting removes it.
Where training fails and MFA covers it
The reverse also holds. Verizon's researchers found the click rate on their own phishing tests largely unaffected by training alone - people still click after the video. A workforce is never at zero: KnowBe4's 2025 benchmark of 67.7 million simulations across 14.5 million users found a 33.1% phish-prone rate before training, still about 4.1% after twelve months of consistent training and simulation. MFA is what turns that residual 4% from an account takeover into a non-event - provided it is phishing-resistant (app-based or passkey) rather than SMS where possible.
The defence that actually matches the threat
Think of it as two layers over the same attack:
- Reduce the clicks. Monthly micro-training plus realistic phishing simulations, with coaching on failure and an easy report button. Benchmark data shows click rates falling roughly 40% in 90 days and up to 86% over twelve months.
- Reduce what a click costs. Phishing-resistant MFA on every account, passkeys where available, and session policies that short-lived cookies cannot easily abuse.
Neither layer alone closes the gap. Together they address the 60% human element that breach data keeps finding.
How to measure both layers
- Click rate and report rate on simulations, tracked over time in human risk reporting - the trend matters more than any single test
- MFA coverage: what share of accounts, especially admin and finance accounts, have phishing-resistant second factors
- Where the two overlap: which staff who failed the last simulation also lack app-based MFA - that intersection is your actual risk list
A gap assessment maps both layers in one pass and shows which of the two is currently the weaker one in your business.
FAQ
Does multi-factor authentication stop phishing emails? No. MFA stops stolen credentials from being enough; it does nothing to the email that arrives. The phish still lands - and modern techniques phish the MFA step itself.
What kind of MFA can phishing not beat? Phishing-resistant methods - hardware security keys and passkeys - bind the login to the genuine site, so a fake login page cannot relay them. SMS codes are the weakest second factor because of SIM swaps.
If we have MFA everywhere, do we still need security awareness training? Yes. Around 4% of a trained workforce still clicks (KnowBe4 2025), and techniques like OAuth consent phishing and session-cookie theft bypass MFA entirely. Training reduces clicks; MFA reduces the cost of the residual ones.
What should a small business do first - MFA or training? MFA first, because it is hours of work for the largest single risk reduction (Microsoft: over 99.2% of account compromise attacks blocked). Start training and simulations in the same month and run them continuously.