MFA Under Siege: Real Evasion Tactics and How to Build an Impenetrable Defense

MFA Under Siege: Real Evasion Tactics and How to Build an Impenetrable Defense

Multifactor authentication (MFA) has become the cornerstone of enterprise security, but its implementation is far from perfect. Despite 87% of large enterprises using it, cybercriminals have developed sophisticated methods to bypass it, from authentication fatigue to cookie theft. In this analysis, we break down the most common attack techniques and offer a roadmap to strengthen your MFA strategy.

MFA security analysis

The MFA Paradox: More Adoption, More Vulnerabilities

Multifactor authentication (MFA) is undoubtedly one of the most powerful tools in modern cybersecurity. However, its implementation is often deficient, sporadic, and inconsistent, which not only reduces its effectiveness but also adds friction to user workflows. This combination of factors creates a breeding ground for attackers to exploit system weaknesses.

Recent incidents, such as the AI-driven phishing attack that managed to steal cloud keys and SSH credentials, or the case of the AI-based attack that leveraged Claude Code, demonstrate that even the most experienced providers are not safe. The series of attacks against Okta in 2023, which resulted in the theft of GitHub source code and the compromise of a support portal, underscores the severity of the problem.

Despite these challenges, MFA has evolved toward more user-friendly methods, such as passwordless authentication. Major providers like Google and Microsoft have driven its adoption, but the reality is that many companies still do not implement phishing-resistant methods. According to a 2025 JumpCloud survey, 87% of large enterprises use MFA, but only a third of small ones do. More alarming is Cisco's finding: although 87% of respondents consider phishing-resistant MFA essential, less than 20% have implemented it.

Main Threats to MFA and How They Operate

Attackers have found vulnerabilities in virtually every element of the IT infrastructure. The complexity of the modern authentication flow—including web portals, mobile apps, AI interfaces, and APIs—offers multiple interception points. Below, we break down the most common techniques.

Authentication Fatigue: The Art of Exhausting the User

Authentication fatigue, also known as push bombing or prompt bombing, involves rapidly sending numerous authentication requests until the user, tired, approves one. This attack was key in the Uber incident in 2022. The irony is that the more MFA is used, the more likely this attack is to succeed, as users become accustomed to receiving constant notifications.

This is one of the reasons SMS has long been considered an insecure second factor. PayPal, for example, will eliminate SMS-based MFA in 2026. Fatigue can also exploit deficiencies in authentication policies, making it a persistent threat.

The combination of social engineering with phishing (smishing or vishing) is another common tactic. Attackers trick users into revealing their MFA tokens, often directing them to fake websites or proxy servers that capture one-time codes. SIM swapping is also a technique used to redirect codes to the attacker's phone.

Changes in user behavior, such as the rise of remote work, are exploited by cybercriminals. Arctic Wolf notes that social engineering combined with MFA fatigue creates a false sense of trust, increasing the attack's effectiveness. Additionally, account recovery and password reset processes have become frequent targets.

MFA attack techniques

Cookie Theft: Hijacking Authenticated Sessions

The theft of authentication cookies or tokens is another attack vector. Attackers can intercept this data through fake login pages or man-in-the-middle proxies. A recent Joomla compromise demonstrated that many websites do not enforce idle time limits, allowing attackers to steal cookies from already authenticated devices and bypass MFA.

KnowBe4 explains that the authorization process cannot verify whether the user holding the token is legitimate, which is exploited by attackers. This vulnerability underscores the importance of implementing stricter session controls.

Attacks on Weak Authentication: The Easiest Link to Break

Targeting users who do not use MFA or applications with weak passwords remains an effective tactic. The Akira ransomware, for example, infiltrated organizations using Cisco VPNs without MFA, employing brute-force attacks. The Colonial Pipeline attack in 2021 was due to the compromise of a single password on a legacy VPN.

Forgotten service accounts or accounts of employees who no longer work at the company are also common targets. Attackers take advantage of already authenticated IP addresses or devices, or set up proxy servers to intercept MFA codes.

Strategies to Harden Your MFA: Beyond the Basics

To ensure security through MFA, it is necessary to pay attention to details and adopt a holistic approach. Here are six key strategies.

1. Know Exactly What You Are Protecting

Before implementing MFA, security teams must identify critical resources. CISA recommends prioritizing FIDO-compliant systems, such as physical security keys and advanced biometric controls. However, Kevin Surace, CEO of Token.com, warns that MFA without biometric data does not verify real identity, only possession of a device. Therefore, it is essential to evolve toward methods that verify identity in real time.

Microsoft has already introduced conditional access and risk-based authentication to combat advanced evasion techniques, such as token theft and session hijacking. This approach could be a model for other companies.

2. Adopt an Adaptive Authentication Approach

Authentication should be based on continuous risk assessments, dynamically reinforcing security requirements based on user actions. Traditional single-checkpoint models are obsolete. Adaptive authentication products integrate MFA into their processes and can request passwordless verification in high-risk situations, such as adding a new beneficiary to a bank account.

3. Strictly Control Access Rights

It is essential to periodically review user and application access rights. Employees should only have access to the data necessary for their roles. However, over time, permissions can accumulate and become obsolete. Regular auditing can prevent excessive access and reduce the attack surface.

MFA protection strategies

4. Analyze Your MFA Workflow

Gerhard Giese of Akamai already noted in 2021 that MFA does not always prevent credential stuffing attacks. It is essential to review authentication flows and login screens to prevent attackers from discovering valid credentials by analyzing server responses. Implementing bot management solutions can also make it harder for cybercriminals.

5. Strengthen the Password Reset Process

Password reset is a historical weak point. Many websites do not have a second 2FA verification layer in this process, or do not force users to use it. Mitnick Security recommends implementing more effective MFA, setting limits for failed attempts, and avoiding password reuse.

6. Protect High-Value Targets

Identify users with additional privileges, such as IT administrators, in-house lawyers, and HR managers. These groups are valuable targets for cybercriminals and should be a priority in MFA implementation. CISA suggests that these accounts should be the first to be protected.

MFA as Part of a Comprehensive Security Strategy

Multifactor authentication should be a critical component of any company's security infrastructure. However, it is not a magic solution. Recent attacks demonstrate that cybercriminals adapt quickly. Therefore, it is essential to combine MFA with other measures, such as adaptive authentication, access control, and continuous employee training.

At ForgeNEX, we understand the complexity of implementing robust security solutions. If your company is looking to optimize its IT infrastructure, we recommend exploring our articles on advanced Microsoft Azure solutions and how to build your own AI SRE. Additionally, efficient resource management is key: check out our guide on expense control and energy and telecom management to optimize your operations.

Security is not a destination but a continuous journey. Stay alert, adapt your strategies, and protect what matters most.


Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.

Share: