Starting in mid-2024, Amazon will require all AWS (Amazon Web Services) premium accounts to use multi-factor authentication (MFA) for even greater protection against data breaches.
See also: Retool attributes breach to Google Authenticator MFA cloud sync feature

MFA provides an additional layer of security to prevent unauthorized access, even if attackers steal an account's credentials. Since 2021, Amazon has been offering free MFA security keys to eligible AWS customers in the United States. In November 2022, it added more flexible MFA options to the platform, allowing up to 8 MFA devices to be registered per account.
Failure to use multi-factor authentication to protect cloud assets can lead to unauthorized access, compromise of sensitive data stored in AWS services, loss of service availability due to malicious configuration modification or deletion of critical resources, and more. Amazon has determined that the simplest way to mitigate risks and reduce the attack surface on AWS is to enforce MFA, starting with the most critical user class.
According to Amazon's announcement, "starting mid-2024, customers signingintoneed the to enable MFA to proceed."
“Customers who need to enable MFA will be notified of the upcoming change through multiple channels, including a prompt when they sign in to AWS.“
See also: Amazon: Sent the wrong email for Mastercard gift cards

Amazon has announced that this requirement will be expanded to additional accounts and use cases as new features to make MFA easier to adopt and manage. Finally, Amazon recommends that customers choose phishing- MFA technologies, such as security keys, although MFA authentication apps work just as effectively.
Security keys that comply with the FIDO U2F or FIDO2/WebAuthn standards are inherently resistant to reverse proxy and man-in-the-middle, which are currently on the rise. During the authentication process, the security key responds to challenges it receives from the server using its private key, while also checking the origin of the website. In the event that there is a problem with the origin, possibly due to a reverse proxy attack, the key will not sign the challenge, preventing the leakage of valuable data.
For more information about MFA support in AWS and instructions for setting up protection for your account, check out Amazon's user instructions page
See also: Amazon to invest billions of dollars in Anthropic
Multi-factor authentication, also known as MFA, is a security method that requires users to provide two or more verification credentials (or factors) before they can access certain resources. These credentials are typically categorized into three categories: something the user knows (such as a password), something the user has (such as a mobile phone or access card), and a biometric (such as a fingerprint or facial recognition).
How multi-factor authentication works
Multi-factor authentication begins when a user attempts to access a resource, often during sign-in .First, the user enters their username and password. The system may then request a second piece of evidence, such as a code sent via SMS to the user's mobile phone or facial recognition via a computer's camera.
This method, while more complex than a simple password login, offers much higher levels of security. This is because even if an unauthorized user manages to get a user's password, they would also need to have access to the second credential – which is much more difficult.
Source: bleepingcomputer
