The Ultimate Guide to Multi-factor authentication
A curated Indian edition of TechDay news, analysis, interviews, reviews, job moves, and related resources for Multi-factor authentication (MFA).
What to know about Multi-factor authentication
Multi-factor authentication (MFA) is a cybersecurity process that requires users to present multiple forms of verification before gaining access to systems or data, significantly reducing the risk of unauthorized access. With cyber threats on the rise, including data breaches, ransomware, and phishing attacks targeting both individuals and organisations, MFA has become a critical component in digital security strategies.
Recent developments highlight the expanding adoption of MFA across various industries and technologies, from cloud services and identity management platforms to hardware-based security keys and biometric authentication methods. MFA solutions continue to evolve, addressing challenges such as ease of use, phishing resistance, and integration with emerging technologies like AI and cloud computing.
For readers interested in understanding how MFA strengthens digital security, mitigates risks associated with compromised credentials, and supports compliance with cybersecurity standards, these stories offer valuable insights. Exploring MFA-related topics can help individuals and organisations make informed decisions on implementing robust, adaptive authentication measures to protect sensitive information in an increasingly connected world.
Indian Multi-factor authentication News
Regional stories with direct local relevance
BioCatch flags surge in SMS fraud targeting Indian banks
Mobile-led fraud is forcing Indian banks to confront faster scams, bigger attempted transfers and a growing mule network.
Makop ransomware group sharpens tools in India focus
Makop ransomware pivots to India with RDP brute force, privilege exploits and GuLoader as it leans on basic flaws over bespoke tools.
Festive-season cyber fraud surges as shoppers seek discounts
Festive-season cyber fraud is surging across India, with Karnataka alone reporting losses above INR ₹2,000 crores, experts warn.
Sixty-eight percent of Indians faced phishing scams last year
A survey shows 68% of Indians encountered phishing scams last year, amid growing concerns over AI-driven cyber threats and weak security habits.
Saviynt partners with St. Fox to boost identity security in India
Saviynt teams up with St. Fox to enhance identity security in India, targeting rapid digital transformation across key sectors with integrated solutions.
Analyst Insights
Research and market analysis connected to Multi-factor authentication
Deepfake fraud attacks rise 180% as identity checks fail
Mandiant study finds USD $4.3 million annual benefit
Gartner says 40% of governments will create TrustOps
Infobip launches AgentOS platform, targets agentic AI shift
DigiCert updates document trust tool to curb AI fraud
Expert Columns
Why You Need Phone Validation in Your Customer Data Toolkit
When AI accelerates the threat, identity governance cannot afford to stand still
The Hidden Cost of Identity Friction in Retail
Cyber hygiene 101: The big fundamentals
A long time ago in a galaxy far, far away…Cybersecurity was already hard
Why service desks are emerging as a critical security weakness
Stolen credentials don't have to mean a breach
Building security outcomes for small businesses: Why breaches persist despite available tools
Small alert, big defense: Inside a SOC's early-morning response
How phone verification keeps customer data accurate
Interviews
Interviews and video coverage from the networkRecent Multi-factor authentication News
Cloud security report finds gaps differ by provider
Multi-cloud security teams face different risks on AWS, Azure and Google Cloud, with misconfigurations high across all three providers.
Ecommerce fraud pressure rises 33% as AI fuels attacks
Account takeover and card-testing attacks surged as AI lowered the cost and speed of scams, raising pressure on online retailers.
Google Cloud outlines targeted response to cyber threats
Customers will face narrower disruptions as Google Cloud moves to throttle malicious traffic, isolate risky identities and preserve legitimate usage.
Google links UNC6671 to cloud extortion brand shift
Google says the campaign is shifting towards financial and legal firms, with rebranded extortion sites still stealing cloud logins and tokens.
Zero Trust drives biometrics in physical access security
The shift could leave sites exposed unless firms match cyber defences with repeated identity checks at doors and restricted rooms.
Logokit phishing kit builds real-time fake login pages
Victims can be tricked more easily as Logokit now tailors fake login pages in real time, sending stolen credentials to Telegram bots.
Compromised credential monitoring lags threat awareness
Despite widespread concern over stolen logins, only 19% of organisations continuously monitor and automatically remediate exposed credentials.
Attackers exploit trusted credentials in email fraud surge
Email fraud is now the top incident type, accounting for 45% of cases as attackers bypass multi-factor authentication with stolen credentials.
APT28-linked campaign hijacks hotel Wi-Fi for logins
Corporate travellers at hotels and conference centres were quietly sent to fake Microsoft 365 pages after attackers took over guest Wi-Fi gateways.
Manufacturers face new cyber risks from connected factories
Connected factory networks are widening the attack surface, with SonicWall warning that old flaws and weak access controls can expose production systems.
Phishing campaign targets universities & EU bodies
Researchers warn the campaign can bypass multi-factor authentication, putting university and EU-linked accounts at risk of real-time takeover.
Microsoft tops brand phishing list in Q2 2026 report
Attacks are increasingly concentrating on a handful of familiar brands, with Microsoft alone accounting for 23% of phishing attempts in Q2 2026.
Synology launches Surveillance365 for multi-site firms
Businesses running multiple sites can now manage camera networks without on-site servers, as Synology rolls out a cloud service worldwide.
Yubico's YubiKey 5.8 adds digital signing features
The update could let companies use a single security key to approve payments, documents and AI actions without custom cryptography.
1Password launches Claude browser login for AI agents
The update lets AI agents sign in without seeing passwords, easing a major security hurdle for firms automating browser tasks.
WhatsApp GhostPairing attack gives intruders access
Attackers can stay inside WhatsApp accounts after a single fake device approval, exposing messages, calls and contacts without alerts.
Phishing toolkits target Microsoft 365 MFA in surge
Account takeovers are becoming harder to stop as attackers use real-time code theft and fake login pages to bypass Microsoft 365 MFA.
SonicWall urges focus on patch speed over CVE count
The real risk lies in unpatched flaws, as attackers increasingly exploit fixes already available but not yet installed.
Proofpoint spots Entra ID spoofing attack technique
Attackers can now probe Entra ID accounts and passwords at scale without a real app, leaving defenders with little sign-in telemetry.