Here’s a number that should stop you cold. Last year, multifactor authentication was turned on in 97% of credential-based attacks, and it failed to prevent the compromise anyway. That’s from new research covered by Dark Reading, which also found that email attacks have now passed software exploits as the number one way ransomware gets into a business.
Read that again. MFA was on. The criminals got in anyway. If you turned on MFA a couple years ago and mentally checked the “we’re secure” box, this is the post for you.
Why “we have MFA” stopped being enough
MFA was supposed to be the fix. You type your password, then approve a prompt on your phone, and a stolen password alone becomes worthless. For a while that worked well enough that attackers moved on to easier targets.
They didn’t stay gone. They just figured out how to get around the phone prompt. And most of the ways they do it don’t require breaking any technology. They break the person.
How attackers beat MFA now, step by step
There are three plays running against small businesses right now, and none of them need a genius hacker.
Play one: the fake login page that passes your code through. You get an email that looks like it’s from Microsoft, DocuSign, or your bank. You click, you land on a page that looks exactly right, and you type your password. Then it asks for your MFA code, and you type that too. Here’s the trick: the fake page is sitting in the middle, feeding everything you type straight to the real site in real time. The attacker logs in as you at the same moment, and grabs your session so they don’t even need to ask again. Your MFA worked perfectly. It just approved the criminal.
Play two: prompt bombing. The attacker already has your password from a breach dump. They log in over and over, firing off approval prompts to your phone. Ten, twenty, fifty in a row, often at 2 a.m. Eventually someone taps “approve” just to make the buzzing stop, or because they assume it’s a glitch. Done.
Play three: they just ask you nicely. Someone calls claiming to be from IT or a vendor. They’re polite, they know a few real details about your company, and they walk you through “verifying your account.” You read them a code. That code was your MFA. This is the one that’s exploding, because AI makes the scripts and the voices convincing.
Notice what all three have in common. The technology did its job. The weak link was the login flow itself and the human standing in front of it.
Why your current setup probably doesn’t catch this
The most common form of MFA, a code in a text message or a tap-to-approve push, is exactly the kind that these attacks are built to beat. A text code can be typed into a fake page or read aloud to a caller. A push prompt can be spammed until someone caves. Both rely on a human making the right call under pressure, and humans lose that fight often enough that attackers keep doing it.
Your antivirus won’t see any of this either, because there’s no malware involved. Nobody downloaded a file. Someone just logged in with valid credentials and a valid code. From the system’s point of view, that’s a normal Tuesday.
What actually stops it
The good news is there’s a real fix, and Microsoft is now pushing everyone toward it. As of this week, passkeys are the default sign-in method in Microsoft Entra ID, the identity system behind Microsoft 365.
A passkey is a login tied to your actual device and your fingerprint or face. There’s no code to type, so there’s nothing to type into a fake page. There’s no prompt to spam. There’s nothing to read to a caller. If the login isn’t happening on your real device, it doesn’t happen. This kind of MFA is called phishing-resistant, and it earns the name. It shuts down all three plays above.
Here’s what to do, in order:
- Turn on phishing-resistant MFA in Microsoft 365. Passkeys or hardware security keys, not just text codes and push prompts. This is the single biggest thing you can do this month. Setting it up right across your staff is something we handle for clients.
- Kill the weak fallback methods. If passkeys are on but text-message codes still work as a backup, attackers will just target the backup. Turn the old methods off once everyone’s switched.
- Set up alerts for impossible logins. A sign-in from your town at 9 a.m. and another from overseas at 9:05 should trip an alarm and lock the account. That kind of monitoring (part of what we watch for clients) catches the sessions that slip past everything else.
- Tell your team the rule out loud: nobody from IT or any vendor will ever ask you to read a code over the phone. Ever. If someone does, hang up.
MFA isn’t dead. The lazy version of it is. If you set it up years ago and haven’t touched it since, you’re running the exact configuration attackers have spent two years learning to beat.
If you’re not sure what kind of MFA your business is actually running, that’s worth fifteen minutes to find out. Book a free 15-minute consult.