Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Should We Be Rethinking Multifactor Authentication?

KEY POINTS: KEY POINTS: Attacks exploiting multifactor authentication are on the rise. Using MFA fatigue, attackers successfully breached Uber and Okta. Security measures like authentication with biometrics and passwordless logins mitigate risk. Power in Passwordless: Rethinking Multifactor Authentication After Increase in Attacks It’s easy to imagine – your work email prompts a sign-in approval on…

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By Aaron Painter ·
Share

Key takeaways

01

KEY POINTS: KEY POINTS: Attacks exploiting multifactor authentication are on the rise.

02

Using MFA fatigue, attackers successfully breached Uber and Okta.

03

Security measures like authentication with biometrics and passwordless logins mitigate risk.

Get featured

Want to get featured in MarketScale Software & Technology?

Create a free MarketScale workspace and get your company's expertise featured across our Software & Technology coverage. No credit card, no demo required.

Request an invite

KEY POINTS:

  • Attacks exploiting multifactor authentication are on the rise.
  • Using MFA fatigue, attackers successfully breached Uber and Okta.
  • Security measures like authentication with biometrics and passwordless logins mitigate risk.

Power in Passwordless: Rethinking Multifactor Authentication After Increase in Attacks

It’s easy to imagine – your work email prompts a sign-in approval on your phone before you have access. It seems secure, right? One day, you get a prompt while off work and are not logged in to your email. You deny it. It comes up again and again. Each time, you’re careful to deny the request. Let’s say the notifications continue – relentlessly. In this attack, it’s common for users to become careless and accidentally give attackers an opening. The technique is called MFA fatigue or prompt bombing (Tech Target), and there’s been an influx of these attacks.

“Professionals are abuzz on one topic – the failure of multifactor authentication or MFA, as it is commonly known,” said Aaron Painter, CEO, Nametag. MFA has been a part of directives and advice in improving security for digital account access for the last few years. “Recent security breaches at a host of companies, most recently at Uber, have pointed to the rise of what’s known as MFA fatigue,” said Painter.

There are a handful of security measures available to mitigate these attacks. Consider a safety net that locks accounts with multiple attempts within a short time. This measure prevents users from experiencing fatigue. Alternatively, professionals suggest one-time passwords. This step is a higher assurance of factors. “It turns out that adding more factors of authentication to passwords isn’t the right answer. Perhaps the solution is that we need better factors,” said Painter.

Microsoft recommends passwordless solutions, which effectively defend against this and more advanced adversary-in-the-middle attacks (Bleeping Computer). Another source, TechTarget, also suggests adopting a passwordless solution. “Passwordless authentication removes passwords from the process, which can drastically reduce risk.” Other passwordless solutions use biometrics for authentication. Apple and Google’s Face ID exemplifies biometric confirmation. “Plus, passwordless authentication reduces friction and improves UX. It also increases the efficiency of IT and security operations, reducing the amount of time and effort spent handling password resets and account lockouts” (TechTarget).

“The recent Lapsis attack and other critical vulnerabilities like those of Print Nightmare have brought warnings even from the likes of the FBI regarding state-sponsored threat actors using exploits like multifactor authentication,” said Painter. Organizations of all sizes are vulnerable to these attacks, including Okta and Uber (CSO). Like most security measures, cyber attackers eventually find a way around them. Pivoting measures to the latest technology and tactics keeps your company safe and secure.

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

Aaron Painter

Aaron Painter is the CEO of Nametag Inc., the world's first identity verification platform designed to safeguard accounts against impersonators and AI-generated deep fakes. Nametag has become the trusted choice for leading companies seeking to prevent fraud, reduce support costs, and eliminate the frustrations associated with account lockouts and high-value transaction authorizations. Driven by his personal experiences with online fraud and identity theft, Aaron assembled a team of security experts to create the next generation of account protection. Nametag's mission is to bring authenticity to the internet and enable users to build trusted relationships. Nametag believes that security should be centered around the user, and that user identity, like privacy, is a valuable asset that deserves protection. Aaron is a global leader, having lived and worked in six countries across four continents. He has authored a best-selling book titled LOYAL, in which he details his key to leadership: fostering a culture of listening. Aaron has codified and implemented this framework of listening in his businesses, which has led to success across the world.

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

Cloud budgets hit 26% of IT spend, and the hiring plan is shifting to platforms

Cloud budgets hit 26% of IT spend, and the hiring plan is shifting to platforms

Foundry’s 2026 Cloud Computing Study, cited by CIO, reports IT leaders expect 26% of IT budgets to go to cloud computing in the next year and that 74% accelerated cloud migrations in the last 12 months. At the same time, CIO’s coverage of Robert Half Technology’s 2026 IT salary report shows AI/ML engineers at a $170,750 median salary and a striking capability gap, with only 7% of leaders saying they have the capabilities to complete prioritized projects and 65% expecting to upskill existing staff. Separate reporting from Nextgov on senior appointments in the Pentagon CIO office, and Government Technology’s account of Illinois’ multi-agency data-sharing MOU, indicate large organizations are staffing for cloud capability development, operational excellence, and cross-domain data governance, not just for lift-and-shift migrations. For enterprise operators, the operational consequence is clear: cloud programs are increasingly won or lost in internal platform engineering, adoption enablement, and CFO-aligned governance, because those are the chokepoints that determine whether higher cloud spend converts into usable services and measurable outcomes.

  • 01A useful benchmark for 2026 planning: Foundry’s survey puts cloud at 26% of IT budget next year, so showback/FinOps and workload-level chargeback governance can’t stay a side project (per CIO citing Foundry).
  • 02Talent pricing has become an input to architecture decisions. A CIO, citing Robert Half, compared the median pay for AI/ML engineers ($170,750) with systems administrators ($98,000), arguing that platform standardization and self-service guardrails are as much about labor strategy as technology.
  • 03If 65% of leaders expect to upskill to close gaps, the differentiator becomes your internal adoption system, in-app guidance, runbooks, and training telemetry, not the third new tool in the stack (per CIO citing Robert Half; illustrated by Ferring’s Whatfix rollout reported by BankInfoSecurity).

Sep 2, 2026

AI agents are pushing access controls and testing into the data layer

AI agents are pushing access controls and testing into the data layer

Snowflake is warning that dashboard-era access controls do not hold up once AI agents can query and act across datasets, pushing governance closer to the data layer, according to TechTarget’s Computer Weekly. In parallel, TechTarget reported that enterprise AI-agent testing needs to expand beyond pre-deployment checks into continuous monitoring so agents don’t drift beyond prescribed instructions. InformationWeek’s reporting on CISOs at Intuit, Smartsheet and ETS adds the operational risk: unmanaged “AI orphans” and identity sprawl as agent count grows, which shifts near-term workload onto IAM, data governance and platform engineering teams building the guardrails.

  • 01If an AI agent can reach multiple tools, the real control plane becomes the data layer and identity, not the BI dashboard permissions model.
  • 02Agent rollouts that stop at pre-production testing are likely to miss the failure mode operators actually see, post-deploy tool changes that alter what the agent can do.
  • 03“AI orphans” is a practical inventory problem: if teams can’t enumerate agents, they can’t set ownership, secrets rotation, or access reviews on a schedule.

Sep 2, 2026

AI agents are moving from chatbots to running workflows, and ops will feel it first

AI agents are moving from chatbots to running workflows, and ops will feel it first

Salesforce’s Winter ’27 release positions AI agents to run end-to-end workflows inside CRM and collaboration tools, including service case guidance, voice scheduling, and agent-driven commerce search, according to Salesforce. In parallel, NIST’s new AI Agent Standards Initiative is asking for industry input on AI agent security and is drafting guidance on software and AI agent identity and authorization, Federal News Network reported. On the infrastructure side, CoreWeave says it is unifying training, inference, observability, and reinforcement learning so autonomous agents can improve in production, while Cloudflare and Plume data highlighted by Cablefax show non-human traffic and AI agent requests rising sharply, creating measurable capacity and latency planning implications. The operational consequence is that “agent readiness” is becoming a joint program across app owners, security teams, and network operators, with identity, authorization, observability, and traffic management becoming gating items for scaling agents beyond pilots.

  • 01If AI agents are going to run workflows, the gating work shifts from prompt design to identity and authorization, NIST’s early initiative outputs are already centered there.
  • 02Agent traffic is not a rounding error: Cloudflare’s estimate that over half of internet traffic is non-human, plus Plume’s household-level data, is a planning signal for WAN, contact center voice, and Wi‑Fi policies.
  • 03The fastest path to better agents is increasingly “production learning,” CoreWeave’s closed-loop training-to-inference pitch, which raises the bar for observability and regression control in enterprise deployments.

Sep 1, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

Aaron Painter is the CEO of Nametag Inc., the world's first identity verification platform designed to safeguard accounts against impersonators and AI-generated deep fakes. Nametag has become the trusted choice for leading companies seeking to prevent fraud, reduce support costs, and eliminate the frustrations associated with account lockouts and high-value transaction authorizations. Driven by his personal experiences with online fraud and identity theft, Aaron assembled a team of security experts to create the next generation of account protection. Nametag's mission is to bring authenticity to the internet and enable users to build trusted relationships. Nametag believes that security should be centered around the user, and that user identity, like privacy, is a valuable asset that deserves protection. Aaron is a global leader, having lived and worked in six countries across four continents. He has authored a best-selling book titled LOYAL, in which he details his key to leadership: fostering a culture of listening. Aaron has codified and implemented this framework of listening in his businesses, which has led to success across the world.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512