mfa is on the floor for attacking it just dropped

MFA is on. The floor for attacking it just dropped.

Category : | | Posted : Jun 22, 2026

MFA was on. It had been on for years. The training had been done, the boxes had been checked. And someone still got into the business manager’s email.

Leaders deserve a clearer answer than “well, no security is perfect.”

MFA didn’t get weaker. The floor for attacking it dropped.

Five years ago, the attacks that beat MFA needed a real operator on the other end. Skilled, patient, custom tooling. Today those same attacks ship as kits. Sekoia.io tracks the adversary-in-the-middle phishing-kit market at under $350 a month, which means someone with roughly $250 in crypto and a Telegram channel can run kit-quality MFA-bypass campaigns. That’s what changed, and it changes what “we have MFA” actually buys you.

Most of the break-ins come from three familiar attacks.

Start with prompt bombing. An attacker has your password (purchased, phished, or reused from somewhere else) and starts hammering the login button. Your phone buzzes. Approve? No. Buzzes again. Approve? No. Buzzes at 2am. Buzzes during a meeting. Buzzes while you’re driving. Eventually somebody taps yes to make it stop. That’s the whole attack. There’s no genius on the other end.

SIM swapping works differently. An attacker calls your mobile carrier, cons the rep, and gets your phone number moved to a SIM card they control. Your texts now go to them. If your MFA is “we’ll text you a code,” your MFA now belongs to them too. This used to be a targeted attack on crypto traders and executives. It’s now run at scale.

The hardest one to spot is real-time phishing, the adversary-in-the-middle attack those cheap kits are built for. You click a link, land on what looks exactly like your Microsoft 365 login page, type your password, get prompted for your code, type that too. The page in the middle is relaying everything to the real Microsoft login in real time and capturing the session token at the end. You log in successfully. So do they. Microsoft’s 2025 Digital Defense Report attributed 80% of MFA-bypass breaches to session-token theft, which is the prize at the end of that attack.

In all three cases, the user did the MFA. The MFA worked the way it was designed to work. The attacker still got in.

What should a leader do on Monday? Start with work your team or IT provider can begin this week.

Move everyone to phishing-resistant MFA: FIDO2 security keys or passkeys, which only release credentials to the real site, not a lookalike. There’s a temptation to scope this to “high-risk” accounts (finance, HR, IT admins, leadership), but the business manager whose mailbox got hit probably wasn’t on anyone’s high-risk list either. Every account is a way in, and every account leads somewhere.

Turn on number matching, which kills prompt bombing by requiring you to type a two-digit number from the login screen into your phone instead of just tapping approve.

Use conditional access to narrow the windows. Block logins from countries you don’t operate in, require a managed device for admin accounts, re-prompt when something looks off. Conditional access does need careful configuration and ongoing tuning. Otherwise you’ll lock out your bookkeeper the week she’s working from Mexico, so this is a policy conversation, not a one-time toggle.

These controls are already sitting in licenses many organizations pay for. The reason it’s not already in place isn’t usually negligence. It’s that the people running your IT, whether that’s an internal admin or a managed IT services provider, are juggling fifty other fires, and “MFA is on, we’re fine” was a defensible answer until pretty recently.

It’s not a defensible answer anymore.

Here’s the one question worth bringing to your team or IT provider this week:

“Which of our accounts are still using SMS or basic approve/deny MFA, and what’s our plan to move them all to phishing-resistant MFA this quarter?”

Written By

why are we paying nearly the same money for less protection

Why Are We Paying Nearly the Same Money for Less Protection?

Microsoft just raised prices across most of its business SKUs. Business Basic, Standard, E3, E5,…

Read More
too many people have too many keys f30d8b8d

Too Many People Have Too Many Keys

When we onboard a new client, one of the first things we look at is…

Read More