Why Some Two-Step Verification Can Be Phished
Text codes, app codes and push approvals can all be phished by pages that relay them in real time. How these attacks work and which methods resist them.

Two-step verification is one of the best things you can do for an account. But not all methods are equal. If you can type a code into a page, a phishing page can ask for it too, and pass it on before it expires.
How code relay works
- You click a link and reach a fake login page.
- You enter your password. The attacker's system immediately enters it on the real site.
- The real site sends you a code. The fake page asks for it, and you type it in.
- The attacker's system submits the code and captures the signed-in session.
This all happens in seconds, often automatically. Some kits even show you the real site afterwards, so nothing seems wrong.
Methods and how they hold up
| Method | Can a fake page relay it? |
|---|---|
| Text message code | Yes, and it can also be stolen through SIM swap. |
| Authenticator app code | Yes, if you type it into the fake page. |
| Push approval | Yes, if you approve the prompt. See MFA fatigue attacks. |
| Passkey | No. It only works on the real site. |
| Hardware security key | No. It checks the site's address. |
What to do
- Keep your current two-step verification on. It is still far better than a password alone.
- Move important accounts to passkeys or security keys.
- Never type a code into a page you reached from a message link.
- If you did, change the password and sign out of all sessions straight away. See checking sessions and connected apps.
Got a message asking you to verify with a code? Paste it into CyberWatch AI Scan for a free check.
For the full picture, see how to protect yourself from phishing.
Frequently asked questions
Is two-step verification still worth using if it can be phished?
Yes. It blocks most automated attacks and password reuse. Phishing-resistant methods like passkeys and security keys close the remaining gap.
What is an adversary-in-the-middle page?
A phishing page that sits between you and the real site, passing your password and code to the real site instantly and capturing the logged-in session.
Which methods resist phishing?
Passkeys and hardware security keys, because they check the website's real address before responding.
Sources
- Implementing phishing-resistant MFA (fact sheet), US Cybersecurity and Infrastructure Security Agency
- More than a Password, US Cybersecurity and Infrastructure Security Agency
- Multi-factor authentication for your corporate online services, UK National Cyber Security Centre


