After years of data breaches, identity theft, and nonstop warnings from banks and technology companies, people have slowly become familiar with two-factor or multi-factor authentication. Rather than trying to bypass multi-factor authentication altogether, attackers are patiently waiting for victims to complete it themselves. The attack doesn’t defeat multi-factor authentication (MFA). That distinction matters because millions of Americans barely understand why they’re approving those authentication requests in the first place. Multi-factor authentication remains important, but it is no longer the finish line.