< Back to all clusters
[TECHNOLOGY] · United States · 4 sources

started · updated

Hackers Bypass MFA Using Social Engineering, Target Older Americans

Multi-factor authentication (MFA) was promoted as a strong defense against online account theft, with banks, social platforms and employers encouraging its use. Recent attacks have shifted tactics: criminals send fake login pages and legitimate‑looking text messages, then wait for users to approve the MFA prompt, granting the attackers full account access. Older American users are especially targeted because they rely heavily on online banking, healthcare portals and mobile devices, and are less familiar with the nuances of MFA.

At the same time, the security industry is accelerating a move away from passwords altogether. The FIDO Alliance’s passkey standard is now supported across browsers and operating systems, and major tech firms such as Apple, Google and Microsoft are deploying password‑less options like biometric login, magic links and device‑based cryptographic keys. Advocates argue that removing passwords will reduce reuse, phishing, and support‑ticket overload, addressing many of the weaknesses that attackers continue to exploit.

Both trends highlight a growing emphasis on user‑centered authentication solutions while underscoring the need for continued education on social‑engineering threats.

Entities

Apple · FIDO Alliance · Google · Hackers · Older American users