21 July 2026

Ransomware: what MFA actually stops — and what it honestly does not

Colonial Pipeline, Change Healthcare, MGM: most ransomware walks in through an account, not an exploit. Where MFA helps, and where it honestly cannot.

Ask a security vendor about ransomware and you will usually get the same answer: their product stops it. This post is not that answer. Encryption of your servers happens far below the authentication layer, so it is fair to ask whether an authentication product is even relevant. The honest reply is: for the way most ransomware incidents actually begin, yes — and for a meaningful minority of them, no. Knowing which is which is worth ten minutes.

Ransomware rarely breaks in. It logs in.

Year after year, Sophos’ State of Ransomware survey finds the same two root causes trading first place: compromised credentials and exploited vulnerabilities. In other words, in roughly half of real incidents the attacker did not defeat any software at all. They signed in with a valid password, through a front door that asked for nothing else.

Three well-documented cases show what that looks like in practice.

  • Colonial Pipeline, 2021. The attack that shut down the largest fuel pipeline in the United States started with a single password for a legacy VPN account. The account was no longer in active use but still worked, the password had surfaced in a leaked credential dump, and the VPN had no second factor. No exploit, no malware at the perimeter — a login form did exactly what it was told.
  • Change Healthcare, 2024. The breach that paralyzed medical payments across the US began when attackers signed into a Citrix remote-access portal with stolen credentials. The company’s own policy required MFA on external systems; this portal did not have it. The attackers then spent nine days moving through the network before deploying ransomware — more on those nine days below.
  • MGM Resorts, 2023. Attackers talked a help desk into resetting credentials for an employee they had researched on LinkedIn, then deployed ransomware that took slot machines, room keys and reservations offline at a cost MGM put near $100 million. The lesson cuts deeper here: MFA existed, but any second factor a help desk can reset over one phone call is only as strong as that phone call.

None of these began with an unpatched server. All three began with an account.

The days in the middle

Ransomware is the last step of an intrusion, not the first. At Change Healthcare, nine days passed between the first login and the encryption. That window is when attackers do the work that makes ransomware devastating: moving laterally over RDP and SSH, collecting admin credentials, reaching backups.

Almost all of that movement is done with stolen accounts, because logging in is quieter than exploiting. Which means every internal login that demands a phishing-resistant approval is not just a lock — it is a tripwire. An approval request arriving on an administrator’s phone for a login they never started is one of the earliest, clearest breach signals an organization can get, at a point where the incident is still an unauthorized login and not yet a ransom note.

What MFA honestly cannot stop

Now the other half of the truth. In 2023 the Cl0p group ran a mass extortion campaign through a SQL-injection zero-day in MOVEit Transfer, a managed file transfer product. Thousands of organizations were affected. No credentials were phished and no prompts were approved, because the exploit never touched the authentication layer at all.

Authentication cannot help when the attacker goes around the login rather than through it: an unauthenticated remote-code-execution flaw in an exposed appliance, a kernel exploit escalating privileges on a box already reached. That territory belongs to patching, network segmentation, endpoint detection and offline backups — see CISA’s #StopRansomware guide for the full checklist. An authentication vendor claiming to “stop ransomware” outright is selling past the edge of what authentication does.

Where Notakey fits

Notakey covers the entry paths the cases above were built on — as one layer of a defense in depth, not a replacement for the others.

  • The most common front doors get a real second factor. VPN over RADIUS, Windows logins including remote desktop, Linux SSH — the practical guides cover VPN 2FA, Windows remote desktop and SSH via PAM. A leaked VPN password on its own — the entire Colonial Pipeline entry — opens nothing.
  • Approvals are readable, so unexpected ones stand out. Every request shows exactly what is being approved: which system, which action, from where. A prompt the user never initiated is visibly not theirs — the tripwire from the section above, during the days when an intrusion can still be stopped.
  • The key cannot be reset over a phone call. It is generated in the phone’s secure hardware and never leaves it. There is no shared secret a help desk can read out to a convincing caller, which is precisely the gap the MGM attackers used.

What Notakey does not do: patch your Citrix appliance, detect a kernel exploit or restore your backups. If a vendor tells you one product does all of that, keep a hand on your wallet.

See it for yourself

The quickest way to judge the approval flow is to use it once: reading and signing a specific action from your own phone, rather than tapping a context-free prompt.

Try the live demo to sign one in about two minutes, or request a demo and we will map your VPN, SSO or Windows logins to a pilot on your own infrastructure.

← All posts

See your first passwordless login this week

A 30-minute call with an engineer, not a sales deck. We’ll map your VPN, SSO or Windows setup to a working pilot.