FB pixel

Financial institutions stumbling into phishing-resistant MFA gaps, report warns

Categories Access Control  |  Biometrics News
Financial institutions stumbling into phishing-resistant MFA gaps, report warns
 

Financial institutions seem aware that phishing is worsening, but that awareness has not translated into stronger authentication across the workforce.

In a Secret Double Octopus survey, 94 percent of identity and security leaders said their organizations experienced an increase in phishing attempts over the previous year. But only 28 percent of the multi-factor authentication (MFA) used for workforce access was reported to be phishing-resistant.

Despite these gaps, 82 percent of respondents said they were somewhat or very confident that their current authentication controls could mitigate the risk of account takeover.

Two hundred IT, cybersecurity, and identity-security decision-makers in the North American financial services industry took the survey.

The findings definitely do not suggest that financial institutions have ignored the implementation of MFA. They indicate that organizations are operating a fragmented collection of authentication methods with different levels of resistance to phishing.

About 77 percent of respondents said their organizations use one-time passwords, with 76 percent using passwords with push notifications, and 72 percent using hardware security keys or FIDO2.

But the adoption of MFA alone does not indicate how well an organization is protected. Security depends on the proportion of applications and users covered, the strength of the accepted authentication methods, and whether weaker fallback mechanisms are available.

“Strong-sounding MFA is not the same as phishing-resistant MFA, and partial coverage leaves the most sensitive systems exposed,” says Raz Rafaeli, chief executive officer and co-founder of Secret Double Octopus.

This uneven protection becomes clearer when the survey separates modern SaaS applications from legacy and on-premises environments. Respondents estimated that MFA covers 74 percent of their SaaS applications, compared with only 50 percent of their legacy systems and applications.

In addition, respondents estimated that approximately 15 percent of their workforce authentication flows were passwordless, and 10 percent said none of their workforce authentication was passwordless.

The report argues that passwordless authentication does not require financial institutions to replace their older applications. SDO’s ZeroPassword technology can become an integration layer that connects modern, phishing-resistant authentication to legacy and on-premises systems.

The report concludes that financial organizations need to assess authentication at the level of individual applications, user groups, and login paths. An institution may have deployed security keys for privileged administrators, but continue to allow passwords and OTPs for other employees and legacy systems.

8Layers extends pre-seed funding as banks focus on identity risk

Madrid-based cybersecurity startup 8Layers has raised an additional €1 million (approximately US$1.1) to extend its pre-seed financing to €2.5 million ($2.9 million). The round was led by Criteria Venture Tech, the venture capital arm of financial holding company CriteriaCaixa, with Spanish bank Bankinter as a strategic investor.

The funding follows the company’s €1.5 million ($1.7 million) round in 2025, led by JME Ventures, with participation from Lanai Ventures, Draper B1, and Secways.

The earlier round was aimed at developing the technology platform and preparing for European expansion. The latest capital will support its go-to-market strategy and accelerate commercialization across Europe. The company says its platform became commercially available in May 2026.

“We have just launched the platform commercially, and we are very proud to welcome two strategic partners who know first-hand the problem we solve,” says Daniel García Morán, CEO and co-founder of 8Layers.

8Layers brings together three functions that financial organizations address through separate identity security tools: Identity Security Posture Management, Identity Threat Detection and Response, and automated compliance assessment.

Identity Security Posture Management (ISPM) analyzes how identities are configured across an organization. It identifies conditions such as exposed accounts or other weaknesses that could allow an attacker to access sensitive systems.

Identity Threat Detection and Response (ITDR) addresses activity related to those identities. It is intended to detect suspicious behavior or signs that an identity has been compromised and help security teams respond before the attacker can move inside the environment.

The compliance component assesses identity controls against requirements, including Spain’s National Security Framework (ENS), the EU’s NIS2 Directive, and ISO 27001.

Related Posts

Article Topics

 |   |   |   | 

Latest Biometrics News

 

Biometrics consolidation reflects shift to continuous identity

AI-driven fraud is reshaping the biometrics industry. This week’s acquisitions, product launches and market developments all point toward the same…

 

Australia’s national face matching system expands with NSW participation

New South Wales (NSW) is joining Australia’s national face matching network, allowing driver licence and photo card images to be…

 

From behavior to payment: Visa builds trust across the customer lifecycle

Visa’s agreement to acquire BioCatch for $2.4 billion raises an important strategic question: Why would a global payments network invest…

 

Why deepfake detection is becoming trust infrastructure

For many, the word “deepfake” still has a twinge of novelty about it – a hint of science fiction. But…

 

Brazil age assurance challenge overlooks privacy-preserving options

Where there are online safety laws, there is litigation aiming to curb them. So it goes in Brazil, where the…

 

Post-quantum identity expands beyond cryptography

As governments and enterprises prepare for practical quantum computing, the focus has largely been on post-quantum cryptography. IBM is targeting…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Market Intelligence

Featured Company

Biometric Update Podcast

Most Read This Week

White Papers

Latest Webinars

Biometrics Industry Events