Zero Assumptions · Week 2 of 25
Your SMS code just left the building. And your MFA is fine.
A 76% surge in AI-powered phishing bypass kits — and the structural reason why hardware-bound authentication is the only fix.
|
Last week we looked at what happens inside your endpoint when a skilled attacker blinds your EDR before pulling credentials. This week, we step back to the moment before that — the authentication event itself.
The assumption most organisations are still making: SMS OTP or push notifications provide adequate secondary protection against account takeover.
The reality: cybercriminals have industrialised the interception of network-delivered codes. The channel was never the defence — the shared secret is the problem.
|
76%
Surge in AI-powered phishing bypass kits specifically engineered to intercept network-delivered authentication codes in transit — over the 12 months to Q1 2026.
Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026
|
How the intercept actually works
Adversary-in-the-middle (AiTM) toolkits act as transparent proxies between the user and the legitimate service. The user authenticates normally, enters their OTP — and the toolkit captures the resulting session cookie in real time. The attacker never needs the code. They take the authenticated session.
Generative AI has removed the human bottleneck. Earlier campaigns required a skilled operator to act within the OTP validity window. AI now automates the entire conversation layer — producing contextually accurate lures, responding to victim queries, and executing session hijacks without any human involvement at the attacker's end.
|
53%
Of security leaders now cite generative AI as their top identity-specific security concern — displacing stolen credentials from the top position for the first time in report history.
Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026
|
|
The blueprint — why FIDO2 breaks AiTM structurally
FIDO2 hardware keys bind authentication to a specific origin — the exact domain of the service. A phishing proxy presents a different origin. The authenticator refuses to generate a valid signature. There is no code to intercept, no session to hijack. The attack category is eliminated, not mitigated.
SIM-swapping, MFA bombing, push fatigue — all three attack paths close simultaneously. Hardware-bound authentication removes the target, not just the attacker's efficiency.
|
Partner news
Feitian completes post-quantum cryptography upgrade across its full product line
Feitian has completed a hardware-level post-quantum cryptography upgrade across its Smart Cards, PKI Tokens, and FIDO Security Keys — integrating a dedicated PQC co-processor with native support for the ML-KEM and ML-DSA international standards. This is not a firmware patch. It is a chip-level architecture change.
|
Why this matters now — "Harvest Now, Decrypt Later"
Nation-state adversaries are collecting encrypted data today with the intent to decrypt it once quantum computing matures. For organisations handling data with a long security horizon — financial records, patient data, government communications — the quantum threat is not a future problem. The data being collected right now is at risk.
|
For FIDO Security Keys: Hardware-level PQC protection for zero-trust and passwordless deployments. For PKI Tokens and Smart Cards: ML-DSA-based authentication for high-value transactions. Crypto-agility: Runs alongside existing RSA/ECC with no forced cutover. The FT-JCOS chip now holds CC EAL6+ and EMVCo certifications — the highest Common Criteria level available for smart card hardware.
Coming up next week
Week 3 — The helpdesk open door
KBA and a Zoom check feel like a security process. They're actually the most reliably socially-engineered control in your environment.
Week 4 — Sovereign hardware risk
Not all FIDO2 tokens are equal. The full certification comparison table — what CC EAL5+, ANSSI Security Visa, and FIPS 140-3 actually validate.
The authentication layer is where most breaches begin. It is also where they are easiest to close — if you replace the shared secret with a hardware-bound proof.
Mikael Rodin
Managing Director, Ciptor
P.S. Missed Week 1? Start from the beginning at ciptor.com/zero-assumptions