How Attackers Outsmart MFA In 2025
SC Media, Monday, March 24th, 2025
A recent report from Truffle Security uncovered over 12,000 active API keys and passwords embedded within Common Crawl, a dataset used to train large language models (LLMs).
These leaked credentials provided attackers unrestricted access to corporate networks and sensitive databases, completely bypassing multi-factor authentication (MFA).
"Multi-factor authentication is a great idea and an effective control, but realistically, it's nearly impossible for organizations to implement everywhere consistently," said Hed Kovetz, CEO & Co-Founder of Silverfort, during the SC Media webinar Beyond Perimeter Defenses: Closing Identity Security Gaps in 2025.