Attackers Don’t Need to Break Your MFA Anymore. They Just Steal What It Protects.

Abstract illustration of a digital authentication token being intercepted between two network nodes, representing session hijacking that bypasses MFA

Somewhere in your office right now, an employee is logging into email exactly the way they’re supposed to: correct password, MFA prompt approved, green checkmark. Nothing about it looks wrong. And that’s precisely the problem, because the newest wave of phishing kits isn’t trying to guess passwords or wear employees down with repeated MFA prompts anymore. It’s stealing the session that comes right after a real, successful login.

How the attack actually works

The technique is called adversary in the middle phishing, and it’s simpler than it sounds. An employee clicks a link and lands on a page that looks identical to their real login screen, Microsoft 365, a bank portal, whatever the target happens to be. Instead of just harvesting a password, the fake page sits between the employee and the real site, quietly passing every keystroke and every MFA approval through in real time. The employee logs in successfully. The MFA prompt goes through successfully. From the employee’s side, everything worked.

What they don’t see is that the attacker’s proxy just captured the session token issued at the end of that exchange: the piece of data that tells Microsoft or Google “this person already proved who they are, let them in without asking again.” With that token in hand, the attacker doesn’t need the password. They don’t need to beat the MFA a second time. They load the stolen session into their own browser and walk in the front door as your employee.

This isn’t a hypothetical

Microsoft’s security team has been tracking one phishing-as-a-service kit, Tycoon 2FA, that pushed tens of millions of these messages against more than 500,000 organizations in a single month, with turnkey access to the kit selling for around $120. It’s a subscription product now, built for people who don’t need to understand the underlying attack to run it.

The consequences show up fast. In one recent incident tracked by the Cloud Security Alliance, attackers used stolen OAuth refresh tokens tied to a connected app to reach Salesforce data at more than 700 organizations across finance, healthcare, and government, all without a single password being cracked. And it’s worth sitting with this number from Kroll’s breach investigations: 90 percent of organizations that got breached last year already had MFA turned on. MFA was never the problem. It’s that most MFA in use today can be relayed straight through by an attacker sitting in the middle, and it doesn’t know the difference.

What actually closes the gap

None of this means MFA is a wasted investment, its still a lot better than nothing. It means the type of MFA matters more than whether you have it at all. A few things move the needle:

  • Phishing-resistant authentication. Hardware security keys and passkeys built on the FIDO2 standard cryptographically bind the login to the real website, so a proxy page simply can’t relay the exchange. Cisco Duo’s own research puts FIDO2 adoption at only 19 percent of companies today, which means most businesses are still exposed to exactly this attack.
  • Conditional access policies that flag an unfamiliar device or an impossible travel pattern and force a fresh login, rather than trusting a session indefinitely.
  • Shorter session lifetimes and token binding so a stolen token has a small window to be useful before it expires on its own.
  • Active monitoring that catches an unusual sign in pattern in minutes, not weeks later during an audit.

This is exactly the kind of layered defense Cloud9 Tech Solutions builds into a client’s security stack: identity protections, conditional access, and continuous monitoring working together rather than leaning on MFA alone to carry the whole load. It’s also why the monitoring side of an environment matters as much as the tools themselves; our managed IT services team watches for the sign in patterns that give this attack away long before it turns into a real incident.

If your business is running MFA and assuming that box is checked, it’s worth a second look. The attackers already know the difference between MFA that’s phishing resistant and MFA that just feels secure.

Schedule a free security assessment with Cloud9 and we’ll show you exactly where your current setup stands against this kind of attack.