Australia’s cybersecurity agency pushes phishing-resistant MFA after wave of account compromises
A password alone can’t protect your accounts.

Computer breach. By Cybernews/Unsplash.
- 42% of reported security incidents involved compromised accounts or credentials in 2024 and 2025.
- Businesses and users are urged to enable multi-factor authentication across email, banking, and social accounts.
- Passkeys are recommended because they combine a PIN or biometrics with a trusted device.
- If passkeys are unavailable, users should choose another method, such as an authenticator app.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Australian Signals Directorate (ASD) calls on businesses, organizations, and other users to enable multi-factor authentication to reduce the likelihood of a successful cyberattack.
According to Australia’s cybersecurity agency, 42% of all security incidents in the industry, government, and critical infrastructure sector that were reported to the ASD in 2024 and 2025 involved compromised accounts or credentials.
This shows that passwords are no longer enough to protect your corporate data or personal information.
That’s why the cybersecurity agency is calling on business owners and netizens to beef up the security of their accounts by enabling multi-factor authentication (MFA).
“Just one extra step can help prevent a security incident. Lock down your digital life by enabling MFA across your email, banking, and social media accounts, and spread the word about the importance of MFA for personal and professional security,” the ASD says.
To log in to their account, users will need their username and password, as well as a second authentication factor to verify their identity, such as a fingerprint, facial recognition, or a temporary access code sent via SMS or an authenticator app.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The ASD recommends activating passkeys because they combine something a user knows (a PIN or biometrics) and something a user has (a device) to grant them access to trusted accounts, services, and platforms.
If platforms don’t support passkeys, users should enable another form of MFA, such as an authenticator app.
In July, the ASD said that autonomous AI agents are great for boosting cybersecurity, but that human interaction remains essential.
“The findings provide an important insight into the future capabilities of highly capable AI systems and reinforce the need for robust security, governance, and oversight mechanisms in the deployment of advanced cyber capabilities, as well as strong cybersecurity fundamentals,” the cybersecurity agency explained in a blog post.