The Ultimate Guide to Multi-factor authentication
A curated Indian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Multi-factor authentication (MFA).
What to know about Multi-factor authentication
Multi-factor authentication (MFA) is a cybersecurity process that requires users to present multiple forms of verification before gaining access to systems or data, significantly reducing the risk of unauthorized access. With cyber threats on the rise, including data breaches, ransomware, and phishing attacks targeting both individuals and organisations, MFA has become a critical component in digital security strategies.
Recent developments highlight the expanding adoption of MFA across various industries and technologies, from cloud services and identity management platforms to hardware-based security keys and biometric authentication methods. MFA solutions continue to evolve, addressing challenges such as ease of use, phishing resistance, and integration with emerging technologies like AI and cloud computing.
For readers interested in understanding how MFA strengthens digital security, mitigates risks associated with compromised credentials, and supports compliance with cybersecurity standards, these stories offer valuable insights. Exploring MFA-related topics can help individuals and organisations make informed decisions on implementing robust, adaptive authentication measures to protect sensitive information in an increasingly connected world.
Indian Multi-factor authentication News
Regional stories with direct local relevance
BioCatch flags surge in SMS fraud targeting Indian banks
Mobile-led fraud is forcing Indian banks to confront faster scams, bigger attempted transfers and a growing mule network.
Makop ransomware group sharpens tools in India focus
Makop ransomware pivots to India with RDP brute force, privilege exploits and GuLoader as it leans on basic flaws over bespoke tools.
Festive-season cyber fraud surges as shoppers seek discounts
Festive-season cyber fraud is surging across India, with Karnataka alone reporting losses above INR ₹2,000 crores, experts warn.
Sixty-eight percent of Indians faced phishing scams last year
A survey shows 68% of Indians encountered phishing scams last year, amid growing concerns over AI-driven cyber threats and weak security habits.
Saviynt partners with St. Fox to boost identity security in India
Saviynt teams up with St. Fox to enhance identity security in India, targeting rapid digital transformation across key sectors with integrated solutions.
Analyst Insights
Research and market analysis connected to Multi-factor authentication
Deepfake fraud attacks rise 180% as identity checks fail
Mandiant study finds USD $4.3 million annual benefit
Gartner says 40% of governments will create TrustOps
Infobip launches AgentOS platform, targets agentic AI shift
DigiCert updates document trust tool to curb AI fraud
Expert Columns
Cyber hygiene 101: The big fundamentals
A long time ago in a galaxy far, far away…Cybersecurity was already hard
Why service desks are emerging as a critical security weakness
Stolen credentials don't have to mean a breach
Building security outcomes for small businesses: Why breaches persist despite available tools
Small alert, big defense: Inside a SOC's early-morning response
How phone verification keeps customer data accurate
Why digital identity is the new perimeter in a zero-trust world
Bridging the gap: Cybersecurity breakthroughs and imbalances
Account Takeover (ATO) fraud: The hidden threat to your business and how to stop it
Interviews
Interviews and video coverage from the networkRecent Multi-factor authentication News
Logokit phishing kit builds real-time fake login pages
Victims can be tricked more easily as Logokit now tailors fake login pages in real time, sending stolen credentials to Telegram bots.
Compromised credential monitoring lags threat awareness
Despite widespread concern over stolen logins, only 19% of organisations continuously monitor and automatically remediate exposed credentials.
Attackers exploit trusted credentials in email fraud surge
Email fraud is now the top incident type, accounting for 45% of cases as attackers bypass multi-factor authentication with stolen credentials.
APT28-linked campaign hijacks hotel Wi-Fi for logins
Corporate travellers at hotels and conference centres were quietly sent to fake Microsoft 365 pages after attackers took over guest Wi-Fi gateways.
Manufacturers face new cyber risks from connected factories
Connected factory networks are widening the attack surface, with SonicWall warning that old flaws and weak access controls can expose production systems.
Phishing campaign targets universities & EU bodies
Researchers warn the campaign can bypass multi-factor authentication, putting university and EU-linked accounts at risk of real-time takeover.
Microsoft tops brand phishing list in Q2 2026 report
Attacks are increasingly concentrating on a handful of familiar brands, with Microsoft alone accounting for 23% of phishing attempts in Q2 2026.
Synology launches Surveillance365 for multi-site firms
Businesses running multiple sites can now manage camera networks without on-site servers, as Synology rolls out a cloud service worldwide.
Yubico's YubiKey 5.8 adds digital signing features
The update could let companies use a single security key to approve payments, documents and AI actions without custom cryptography.
1Password launches Claude browser login for AI agents
The update lets AI agents sign in without seeing passwords, easing a major security hurdle for firms automating browser tasks.
WhatsApp GhostPairing attack gives intruders access
Attackers can stay inside WhatsApp accounts after a single fake device approval, exposing messages, calls and contacts without alerts.
Phishing toolkits target Microsoft 365 MFA in surge
Account takeovers are becoming harder to stop as attackers use real-time code theft and fake login pages to bypass Microsoft 365 MFA.
SonicWall urges focus on patch speed over CVE count
The real risk lies in unpatched flaws, as attackers increasingly exploit fixes already available but not yet installed.
Proofpoint spots Entra ID spoofing attack technique
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.
WatchGuard warns of shadow AI & weak security habits
Persistent gaps in basic cyber hygiene are leaving small businesses exposed, with most staff reusing passwords and many using unauthorised AI tools.
AI now runs parts of cyber attacks, Check Point says
Defenders face shorter patching windows as Check Point says AI can now turn new flaws into working exploits within hours.
Microsoft makes passkeys default for Entra ID logins
Users relying on SMS or voice for sign-ins will be nudged to passkeys as Microsoft phases out weaker multifactor methods in Entra ID.
OpenAI requires hardware-backed passkeys for cyber access
Users who miss the deadline will lose access to OpenAI's most advanced cyber models, as the firm tightens defences against phishing.
Helix data extortion group linked to BlackFile, ShinyHunters
Businesses face a fresh wave of identity theft-driven extortion as Helix is linked to BlackFile and ShinyHunters through shared infrastructure.