Does MFA stop phishing? What multi-factor authentication does and doesn't prevent

MFA blocks over 99.2% of account compromise attacks (Microsoft) but not phishing itself. Where MFA fails, where training fails, and how the two controls cover each other.

Multi-factor authentication stops more than 99.2% of account compromise attacks, according to Microsoft - but it does not stop phishing. Attackers adapted years ago: they phish the second factor now, not just the password. MFA and security awareness training are not competing controls; they cover each other's blind spots, and this article shows exactly where each one fails so you can see why you need both.

TL;DR

Why this matters

Many small businesses treat MFA as the finish line: once it is on, they think phishing no longer matters. That belief is expensive. If phishing were solved by MFA, credential phishing would not remain the most common initial access vector in breach data - yet Verizon's 2025 DBIR still ranks credential abuse at the top, with the human element involved in roughly 60% of breaches. MFA changes what a phisher has to steal, not whether they try.

What MFA genuinely protects

MFA means a second proof - an app prompt, a code, a security key - on top of the password. Its headline number is real: Microsoft's own research states MFA can block more than 99.2% of account compromise attacks. For bulk attacks - criminals spraying stolen password lists across thousands of accounts - MFA is close to a wall. Every Australian business should turn it on everywhere it is offered: email, accounting, myGov (which now supports passkeys), banking and the company's own systems.

Where MFA fails against phishing

Attackers did not give up when MFA arrived; they moved up a step. Four techniques beat most standard MFA:

The common thread: every one of these requires a human to click, approve, or read out a code. That is the phishing attack surface, and no account setting removes it.

Where training fails and MFA covers it

The reverse also holds. Verizon's researchers found the click rate on their own phishing tests largely unaffected by training alone - people still click after the video. A workforce is never at zero: KnowBe4's 2025 benchmark of 67.7 million simulations across 14.5 million users found a 33.1% phish-prone rate before training, still about 4.1% after twelve months of consistent training and simulation. MFA is what turns that residual 4% from an account takeover into a non-event - provided it is phishing-resistant (app-based or passkey) rather than SMS where possible.

The defence that actually matches the threat

Think of it as two layers over the same attack:

  1. Reduce the clicks. Monthly micro-training plus realistic phishing simulations, with coaching on failure and an easy report button. Benchmark data shows click rates falling roughly 40% in 90 days and up to 86% over twelve months.
  2. Reduce what a click costs. Phishing-resistant MFA on every account, passkeys where available, and session policies that short-lived cookies cannot easily abuse.

Neither layer alone closes the gap. Together they address the 60% human element that breach data keeps finding.

How to measure both layers

A gap assessment maps both layers in one pass and shows which of the two is currently the weaker one in your business.

FAQ

Does multi-factor authentication stop phishing emails? No. MFA stops stolen credentials from being enough; it does nothing to the email that arrives. The phish still lands - and modern techniques phish the MFA step itself.

What kind of MFA can phishing not beat? Phishing-resistant methods - hardware security keys and passkeys - bind the login to the genuine site, so a fake login page cannot relay them. SMS codes are the weakest second factor because of SIM swaps.

If we have MFA everywhere, do we still need security awareness training? Yes. Around 4% of a trained workforce still clicks (KnowBe4 2025), and techniques like OAuth consent phishing and session-cookie theft bypass MFA entirely. Training reduces clicks; MFA reduces the cost of the residual ones.

What should a small business do first - MFA or training? MFA first, because it is hours of work for the largest single risk reduction (Microsoft: over 99.2% of account compromise attacks blocked). Start training and simulations in the same month and run them continuously.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.