You Turned On MFA. Attackers Adapted.
Multifactor authentication is still essential, and it is no longer enough on its own
Executive Summary
Turning on multifactor authentication was one of the best security decisions most businesses ever made, and for a while it stopped account takeovers cold. Attackers have caught up. Using tools that are now cheap and common, they defeat everyday multifactor authentication by tricking an employee into approving a login, or by wearing them down with repeated prompts until they tap approve to make it stop. Having MFA turned on is no longer the same as being protected. This article explains how attackers get past it, why the type of MFA you use matters, and the practical moves that keep your accounts safe.
The Box Everyone Checked
For years the advice was simple and correct. Turn on multifactor authentication and you close the door on the most common attack, which is a stolen or guessed password. Businesses did it, insurers began to require it, and a well-earned sense of relief followed.
It was the right move. It was not the last move. Attackers do not abandon a lucrative business because one lock got harder to pick. They studied it, and the weakest part turned out to be the moment a real person approves a real login.
How Attackers Get Past It Now
Two techniques do most of the damage, and neither breaks any encryption. Both target the person, not the technology.
The first is a fake login page that sits invisibly between the employee and the real service. The employee clicks a link in a convincing message, lands on a page that looks exactly like their normal sign-in, and enters their password. The service sends a genuine prompt, the employee approves it as usual, and in that instant the attacker, relaying every step to the real service, is handed a valid signed-in session. Everything looked normal because almost everything was. The only thing wrong was the address of the page.
The second is simpler. The attacker, already holding the password, triggers the approval prompt over and over. The notifications pile up late at night or during a busy stretch, and eventually someone taps approve to end the nuisance. That single tap is all it takes.
Not All MFA Is the Same
The most useful thing a leader can understand is that multifactor authentication is not one thing. Some forms are far stronger than others, and the difference decides whether the attacks above succeed. The weaker forms, still the most common, are easily relayed or approved by mistake.
- One-time codes sent by text message or read out by an automated call. These can be phished through a fake page, and they are the weakest widely used option.
- A simple approve or deny prompt on a phone app. Better than a texted code, but still open to the tap-to-make-it-stop problem.
The stronger forms are built so that a fake page and a tired thumb are no longer enough.
- Number matching, where the app shows a number the person must type into their phone, so approval takes deliberate attention rather than a reflex.
- Security keys and passkeys, which tie the login to the genuine website and the person’s own device, so a fake page simply cannot use them.
Moving your most important accounts toward the stronger end of this list is the highest-value change most businesses can make this year.
The Part After the Login
There is one more wrinkle. When you sign in, the service hands your device a temporary pass so it does not have to ask again every few minutes. If an attacker steals that pass, through a fake page or malicious software, they can present it and be treated as already signed in, with no password and no prompt. This is why the convenient stay signed in setting is a quiet risk, and why the business should be able to end a suspicious session on demand rather than trust a login forever.
What This Means for a Small Business
The goal is not to distrust MFA. It is to make the MFA you already rely on genuinely hard to get past.
- Upgrade the method, starting with your most valuable accounts. Move away from texted codes and simple prompts toward number matching, security keys, or passkeys.
- Switch off the old sign-in paths. Many services still allow outdated login methods that quietly bypass multifactor protection.
- Shorten the leash. Use settings that weigh where a login is coming from and require signing in again for sensitive access, rather than trusting a session indefinitely.
- Prepare your people for the real attack. Train employees to expect prompts they did not start and pages that look right but arrived through a link.
- Make sure someone would notice. Ensure the business can see and shut down a sign-in that appears from an unexpected place.
The Takeaway
Multifactor authentication is still one of the most important protections a business can have, and turning it off would be a serious mistake. But the version many businesses switched on years ago was built for a threat that has since evolved. The answer is not to remove the lock. It is to upgrade it, and to accept that the strongest link in the chain is still a well-prepared person who recognizes a login that does not belong to them.
How Simulint Helps
Because these attacks succeed at the moment a person acts, the most reliable defense is a workforce that has seen the tricks before. Simulint helps through BlueSphere, which uses AI to run realistic phishing email simulations and deliver employee training built around them. The simulations expose your team to the kinds of messages attackers actually send, and the training turns each one into a teachable moment, so recognizing a suspicious email becomes a habit rather than a lucky guess. The goal is not to catch people out. It is to make careful judgment routine, so the instinct to stop and check is already there when a real message lands.
Learn more about BlueSphere: https://lnkd.in/eE9HTaw8
