Banks Still Treating MFA as Optional. Your Money Pays the Price.
Last May, professional fraudsters dismantled an 84-year-old woman's financial life in a matter of days. They drained $30,000 from her bank accounts, broke into her Gmail, and set up filters to quietly bin any alerts from her bank or retirement provider so she wouldn't notice. She only found out because her retirement account flagged a suspicious transaction first.
The woman is my mother. And none of it would have happened if the institutions holding her money had simply required multi-factor authentication.
The mechanics were depressingly familiar. She reused passwords across accounts. At least one of those accounts had been caught up in a data breach years earlier, meaning her credentials were almost certainly floating around on some dark web dump. From there, getting into her bank and Gmail wasn't exactly a challenge. The thieves knew exactly how much they could move each day without triggering automatic limits, siphoning funds through a mix of withdrawals and transfers to an account she'd never heard of.
When she called her bank's fraud department, they asked whether a family member might have done it. Then put her on hold. Then again. Then routed her through the kind of phone tree that seems specifically designed to make people give up. Weeks later, after investigation, the bank did restore the funds. She was lucky. There is no legal guarantee they had to.
Under US Consumer Financial Protection Bureau rules, you have 60 days from your bank statement to dispute a transaction. The bank has 45 days to investigate. After that, they can simply decide the transactions looked legitimate and decline to pay out. At that point your options are a lawyer and a lawsuit, which is apparently a thriving enough niche that a quick search turns up dozens of specialists in most cities.
The optional security problem
Here's what's maddening. Banks already understand the concept of mandatory security. They won't let you transact without a password. They won't issue an ATM card without a PIN. They know a minimum threshold exists. They've just decided that threshold stops well short of a second authentication factor.
"Many consumers assume every bank requires 2FA, but that's not the reality," says Gregory Shein, CEO of fintech SaaS company Nomadic Soft. "Some financial institutions still treat it as an optional feature because they're balancing security against friction. Every extra login step can reduce conversions, increase support tickets, and frustrate less technical customers."
That calculation is being made with other people's money. PNC requires MFA. Bank of America, Chase, Capital One, and Citibank leave it as optional. Google, despite being the world's largest email provider and a default target for account takeovers, also leaves MFA optional.
The friction argument does have some grounding in reality. Andrew Shikiar, CEO of the FIDO Alliance, which advocates for stronger authentication standards, acknowledges the tension. "Different segments of the population adopt technology faster or slower. If I'm a bank, I have to consider that very closely because I don't want to lose any banking relationships. So there are concerns around friction that have held some banks back from pushing this more aggressively."
Fair enough. But at some point the cost of optional security shows up as real money leaving real accounts.
Not all MFA is equal
Microsoft claimed back in 2019 that MFA blocks 99.9% of account attacks. That figure has been contested, and with good reason. One-time passcodes sent via SMS or email, the most common form of MFA, have well-documented weaknesses. SIM-swapping attacks let criminals port your phone number to a device they control, intercepting your texts. Phishing sites that mimic bank login pages can capture OTPs in real time. If your email isn't secured independently, an OTP sent there is only as safe as the inbox receiving it.
"OTP is just another password," says Shikiar. "A shorter-lived one, but really just another password. And there are usability issues too. You're juggling between mobile and desktop. It's insecure, inefficient, and a genuinely poor user experience."
The current best practice is passkeys: cryptographic key pairs where the private key lives on the user's device and the public key sits on the server. Authentication requires a PIN, biometric input like a fingerprint or face scan, or a physical security key such as a YubiKey. Passkeys can't be phished because there's nothing to hand over to a fake website. They can't be intercepted in transit. They're what the industry calls phishing-resistant MFA.
Several major banks, including Chase, Wells Fargo, US Bank, and Bank of America, are apparently rolling out passkey support according to the FIDO Alliance. Chase's mobile app already uses biometric login. But Chase's website still only offers OTP via SMS, email, or phone call. Which means if someone targets the web login, there's no biometric challenge in sight. And if the user hasn't enabled any MFA at all, the door is even wider.
This is the core problem. Security that only exists in one channel isn't really security policy, it's a patch. A thief will just use the unprotected channel. If MFA is optional, most people won't turn it on, and thieves know that. The weakest entry point is the one that gets used.
Shikiar is measured about the timeline: "I don't expect banks to be mandating passkeys and only passkeys for some time, but the more they push them, the more adoption grows, and the sooner it becomes a de facto default."
That's diplomatic. What's less diplomatic is that while banks weigh up friction metrics, actual customers are losing real money to attacks that better authentication would have stopped. And when banks do reimburse those losses, which isn't guaranteed, they're absorbing costs they helped create.
The door to my mother's financial life was left open by design. She made mistakes, yes. But the institutions holding her money knew better and chose convenience anyway.