← Back to News

Phishing in practice: what MFA actually prevents

Multi-factor authentication (MFA) has been considered mandatory for years — and rightly so. In a medical practice, where staff work daily with e-mail, patient portals, KIM mailboxes and cloud services, it is one of the most effective measures against account abuse. What many people don’t realise: MFA is not just MFA. Depending on the method you use, you are protected against different kinds of attacks — and not every commonly used variant holds up against modern phishing.

What’s different about phishing in 2026

Classic phishing — a convincing e-mail with a link to a fake login page — still works. What’s new is the real-time variant: attackers run a so-called reverse proxy between the victim and the real login page. The victim enters their username, password, and even the one-time code from the authenticator app — and the attacker forwards all of it to the real site in real time. At the end of the chain, the attacker holds the authenticated session. Software-based factors such as SMS TANs or TOTP codes (Google Authenticator, Microsoft Authenticator) cannot withstand this kind of attack. The BSI therefore explicitly rates them as not resistant to real-time phishing.

What actually protects you: phishing-resistant methods

The key is MFA where the second factor cannot be “forwarded” — meaning it is bound to the real domain you intend to log into. According to the BSI, three methods meet that bar:

  • FIDO2 tokens (e.g. YubiKey, Titan Security Key): a small USB or NFC stick. The token signs a login only if the domain the browser is talking to matches the domain the token was originally registered with. A phishing domain simply doesn’t get a valid response.
  • Passkeys: the same cryptographic principle, just without a separate piece of hardware — the private key lives encrypted in the Apple Keychain, in Google Password Manager or in a password manager app, and is unlocked with Touch ID / Face ID / Windows Hello. From a user perspective: more convenient than a password. From a security perspective: as good as a FIDO2 token.
  • Chip-TAN and ID-card-based methods: relevant for online banking and a few government services — rarely the main case in a practice.

From the BSI’s perspective, passkeys are a very secure authentication solution because they fully replace passwords and, through the use of cryptographic key pairs, prevent phishing attacks.

What that means for the practice

For an average practice with five to fifteen login accounts (M365, KIM, practice software, banking, insurer portals, scheduling tools…), the following approach is usually enough:

  1. Inventory. Which accounts exist? Who has access? Which MFA is currently set up? A simple table will do.
  2. Prioritise. M365 mailbox, KIM, banking, practice-software admin — these are the critical accounts. Move them to passkeys or FIDO2 first.
  3. Define a backup method. What happens if a staff member loses their token? Without that plan, you lock yourself out.
  4. Turn off SMS TANs. Where possible, replace them — SMS codes are vulnerable to SIM swapping and the BSI rates them noticeably weaker.

What about “convenient”?

There’s a pleasant truth here: passkeys are actually faster in daily use than the password + authenticator-code combo. One look at the fingerprint sensor or face recognition — done. Staff who are sceptical at first usually become the strongest advocates within two weeks. If you work on Macs and iPhones anyway, the technical bar is especially low: Apple devices support passkeys throughout the Keychain.

What we recommend

If you’re “only” using a TOTP code from an authenticator app today, you’ve already taken a meaningful step — please don’t read this article as “all of that was for nothing”. But for business-critical accounts (especially anything touching patient data or money flows) it’s worth the effort to move to phishing-resistant methods. We’re happy to help with picking the right hardware tokens, rolling them out across the team, and documenting things for your security and data-protection concept.

Sources

  1. BSI (German Federal Office for Information Security): Assessment of 2FA methods — Technical review. bsi.bund.de
  2. BSI: #nis2know — Multi-factor authentication and secured communication. bsi.bund.de
  3. BSI: Technical Guideline TR-03107 — Requirements for authentication solutions. bsi.bund.de · PDF
  4. BSI press release, 30.01.2026: Effective protection of user accounts — Change-your-password day needs an update. bsi.bund.de

Related articles

Secure MFA for your practice — without friction in daily work.

We review your accounts, recommend the right method, and walk you through the rollout.

Request consultation