Credentials are STILL getting compromised every day. Phishing is still common, and so are re-used (previously breached) passwords. Traditional methods of username/password authentication are trash: easily broken. MFA is our stop-gap until there is a better way that is ubiquitous.