Zero Assumptions #2: Your MFA is already being intercepted.


Zero Assumptions · Week 2 of 25

Your SMS code just left the building.
And your MFA is fine.

A 76% surge in AI-powered phishing bypass kits — and the structural reason why hardware-bound authentication is the only fix.

Last week we looked at what happens inside your endpoint when a skilled attacker blinds your EDR before pulling credentials. This week, we step back to the moment before that — the authentication event itself.

The assumption most organisations are still making: SMS OTP or push notifications provide adequate secondary protection against account takeover.

The reality: cybercriminals have industrialised the interception of network-delivered codes. The channel was never the defence — the shared secret is the problem.

76%

Surge in AI-powered phishing bypass kits specifically engineered to intercept network-delivered authentication codes in transit — over the 12 months to Q1 2026.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

How the intercept actually works

Adversary-in-the-middle (AiTM) toolkits act as transparent proxies between the user and the legitimate service. The user authenticates normally, enters their OTP — and the toolkit captures the resulting session cookie in real time. The attacker never needs the code. They take the authenticated session.

Generative AI has removed the human bottleneck. Earlier campaigns required a skilled operator to act within the OTP validity window. AI now automates the entire conversation layer — producing contextually accurate lures, responding to victim queries, and executing session hijacks without any human involvement at the attacker's end.

53%

Of security leaders now cite generative AI as their top identity-specific security concern — displacing stolen credentials from the top position for the first time in report history.

Source: HYPR / S&P Global — State of Passwordless Identity Assurance 2026

The blueprint — why FIDO2 breaks AiTM structurally

FIDO2 hardware keys bind authentication to a specific origin — the exact domain of the service. A phishing proxy presents a different origin. The authenticator refuses to generate a valid signature. There is no code to intercept, no session to hijack. The attack category is eliminated, not mitigated.

SIM-swapping, MFA bombing, push fatigue — all three attack paths close simultaneously. Hardware-bound authentication removes the target, not just the attacker's efficiency.

Partner news

Feitian completes post-quantum cryptography upgrade across its full product line

Feitian has completed a hardware-level post-quantum cryptography upgrade across its Smart Cards, PKI Tokens, and FIDO Security Keys — integrating a dedicated PQC co-processor with native support for the ML-KEM and ML-DSA international standards. This is not a firmware patch. It is a chip-level architecture change.

Why this matters now — "Harvest Now, Decrypt Later"

Nation-state adversaries are collecting encrypted data today with the intent to decrypt it once quantum computing matures. For organisations handling data with a long security horizon — financial records, patient data, government communications — the quantum threat is not a future problem. The data being collected right now is at risk.

For FIDO Security Keys: Hardware-level PQC protection for zero-trust and passwordless deployments. For PKI Tokens and Smart Cards: ML-DSA-based authentication for high-value transactions. Crypto-agility: Runs alongside existing RSA/ECC with no forced cutover. The FT-JCOS chip now holds CC EAL6+ and EMVCo certifications — the highest Common Criteria level available for smart card hardware.

Coming up next week

Week 3 — The helpdesk open door
KBA and a Zoom check feel like a security process. They're actually the most reliably socially-engineered control in your environment.

Week 4 — Sovereign hardware risk
Not all FIDO2 tokens are equal. The full certification comparison table — what CC EAL5+, ANSSI Security Visa, and FIPS 140-3 actually validate.

The authentication layer is where most breaches begin. It is also where they are easiest to close — if you replace the shared secret with a hardware-bound proof.

Mikael Rodin
Managing Director, Ciptor

P.S. Missed Week 1? Start from the beginning at ciptor.com/zero-assumptions

Kungsporten 4A, 427 50 Billdal, Sweden
Unsubscribe · Preferences

Ciptor

The 2026 threat landscape doesn't care about your 2024 budget. It only cares about your vulnerabilities. Join 10,000+ infrastructure leaders securing the future.

Read more from Ciptor

Zero Assumptions · Week 9 of 25 · Pillar 2: Software stack & contextual risk Your SIEM fired an alert at 09:14.Your EDR caught the same attack at 09:24. Two tools. Same attacker. Ten minutes apart. Neither told the other. Your analyst saw two separate alerts in two separate consoles and triaged them as two separate incidents. The attacker had already moved. In weeks 6, 7, and 8 we covered the operational gaps between assessment cycles, session windows, and board oversight. This week we move...

Zero Assumptions · Week 8 of 25 · Pillar 2: Software stack & contextual risk Your board approved the security budget.That means they've fulfilled their NIS2 obligation. NIS2 Article 20 does not ask your board to approve a budget. It requires management bodies to oversee, be trained in, and be personally liable for your organisation's cybersecurity risk management. Most boards have done none of these things. Most CISOs have not told them. In every previous volume of this series, the assumption...

Zero Assumptions · Week 7 of 25 · Pillar 2: Software stack & contextual risk Your morning login was legitimate.So the session running at 17:00 must be too. Session tokens are hijacked, not phished. Once an attacker has your token, they don't need your password, your MFA, or your hardware key. They already passed authentication. The question is whether your SOC finds them before they find what they came for. Last week we covered identity drift — the entitlement state that diverges from policy...