Skip to content
OGERIA — Observatory of Global Evidence on Risks in AISynthesis report · 2026 ed.
Updated 2 Oct 2026

Chapter 06 · Protection

Phishing-resistant second factor

Two physical FIDO keys —one as backup— on the accounts that anchor your digital identity: email, bank, password manager. Someone can talk you into reading out a six-digit app code; they cannot talk you out of a key.

Level
Personal
Cost
Low cost
Effort
Hours
Evidence
Observed

What it does not solve

It intervenes in no catastrophic mechanism: a key protects your account, not the system. It also does not cover someone impersonating you to a third party, nor does it help when the fraud arrives by a route that asks for no credentials.

It works if the attack is aimed at getting into an account of yours. CISA ranks the forms of second factor from strongest to weakest and is emphatic: the phishingPhishingA scam by email or message that poses as someone you trust so that you hand over a password or some data, or click where you should not.For exampleThe email that looks like it comes from your bank and urgently asks you to “confirm your details”.-resistant factor is the gold standard, and FIDO/WebAuthn and PKI are the two forms that meet it. Against them, push bombing, SS7 and SIM swapping do not apply [244]Implementing Phishing-Resistant MFACybersecurity and Infrastructure Security Agency · 2022 · official documentView source ↗Accessed on 9 September 2026.

It does not work if the fraud does not go through your credentials. And watch out for the intermediate rung: the six-digit code from an authenticator app is vulnerable to phishing, because somebody can talk you into reading it out in real time. SMS sits at the bottom of that table, as a last option, and its real risk is not being useless —it is better than nothing— but leaving you with the feeling of having solved the problem.

Evidence. High and from an official primary source, on an observed vectorVectorThe path by which a risk moves from the screen into the world: biological, cyber, military, economic, political, epistemic or loss of control. In this observatory, each vector has its own colour.For exampleA burglar can get in through the door, the window or the roof. The burglar is the risk; the door, the window and the roof are the vectors.: this already happens, it is not projection. The FBI documents impersonation of senior officials with AI-generated voice and recommends turning on the second factor and never disabling it [394]Senior US Officials Impersonated in Malicious Messaging CampaignFederal Bureau of Investigation; Internet Crime Complaint Center · 2025 · official documentView source ↗Accessed on 9 September 2026.

Cost. Low, and always two keys: one as a backup, because losing the only one means being locked out of your own digital life.

What it does NOT solve. Nothing catastrophic. A FIDO key intervenes in no scenario on this site; it intervenes in the concrete way AI risk reaches an ordinary person today, which is a different thing and also matters.

Works if…

  • AI as normal technology · Works

    This is exactly the harm this scenario predicts and the one already materialising for ordinary people today.

  • Catastrophe through misuse · Partial

    It shrinks your surface against campaigns already using agents, but does nothing to the offensive capability or the attacker's target.

Does not work if…

  • Power grab by a small group · Does not work
  • Rapid loss of control · Does not work

See in the protection matrix →Report a mistake in this entry →

Sources

  1. [244] Implementing Phishing-Resistant MFA · CISA 2022
  2. [394] Senior US Officials Impersonated in Malicious Messaging Campaign · FBI IC3 2025

Ask OGERIA

It answers only with what the observatory publishes and can be wrong: check the entries it cites. Your questions are sent to an AI model, so don't write personal data. More in the privacy policy.

Up to 500 characters.

Support OGERIA on Ko-fi

The payment is processed by Ko-fi, not by this site. Open on ko-fi.com