Blog/Phishing

Why Some Two-Step Verification Can Be Phished

Text codes, app codes and push approvals can all be phished by pages that relay them in real time. How these attacks work and which methods resist them.

CyberWatch AI2 October 2026 · 2 min read
An open padlock among scattered keyboard keys

Two-step verification is one of the best things you can do for an account. But not all methods are equal. If you can type a code into a page, a phishing page can ask for it too, and pass it on before it expires.

How code relay works

  1. You click a link and reach a fake login page.
  2. You enter your password. The attacker's system immediately enters it on the real site.
  3. The real site sends you a code. The fake page asks for it, and you type it in.
  4. The attacker's system submits the code and captures the signed-in session.

This all happens in seconds, often automatically. Some kits even show you the real site afterwards, so nothing seems wrong.

Methods and how they hold up

MethodCan a fake page relay it?
Text message codeYes, and it can also be stolen through SIM swap.
Authenticator app codeYes, if you type it into the fake page.
Push approvalYes, if you approve the prompt. See MFA fatigue attacks.
PasskeyNo. It only works on the real site.
Hardware security keyNo. It checks the site's address.

What to do

  • Keep your current two-step verification on. It is still far better than a password alone.
  • Move important accounts to passkeys or security keys.
  • Never type a code into a page you reached from a message link.
  • If you did, change the password and sign out of all sessions straight away. See checking sessions and connected apps.

Got a message asking you to verify with a code? Paste it into CyberWatch AI Scan for a free check.

For the full picture, see how to protect yourself from phishing.

Frequently asked questions

Is two-step verification still worth using if it can be phished?

Yes. It blocks most automated attacks and password reuse. Phishing-resistant methods like passkeys and security keys close the remaining gap.

What is an adversary-in-the-middle page?

A phishing page that sits between you and the real site, passing your password and code to the real site instantly and capturing the logged-in session.

Which methods resist phishing?

Passkeys and hardware security keys, because they check the website's real address before responding.

Sources

  1. Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
  2. More than a Password, US Cybersecurity and Infrastructure Security Agency
  3. Multi-factor authentication for your corporate online services, UK National Cyber Security Centre
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.