The safety advantages of multifactor authentication (MFA) are well-known, but MFA continues to be poorly, sporadically, and inconsistently carried out, undercutting its effectiveness as a safety instrument whereas usually saddling customers with an additional workflow burden — certainly one of many obstacles to MFA’s success.
Frequent information tales that describe progressive methods to bypass MFA don’t assist, comparable to proof of an AI-fueled phishing assault that discovered cloud keys and SSH entry particulars, and one other case of an AI-based assault that leveraged Claude Code. Even the savviest distributors aren’t immune, as evidenced by a sequence of Okta assaults in 2023 that resulted in stolen GitHub supply code, an contaminated provide chain, and a compromised help portal.
Nonetheless, MFA strategies have gotten simpler to make use of, because of the rising reputation and sophistication of passwordless approaches. Over the previous a number of years, MFA mandates from huge distributors comparable to Google and Microsoft for each workers and clients have helped inspire IT operations to strengthen their authentication practices and encourage complete and steady authentication throughout all purposes.
Based on a JumpCloud 2025 survey, 87% of bigger enterprises recurrently make use of MFA strategies, though solely a few third of smaller companies did the identical. Cisco extra not too long ago discovered that whereas 87% of survey respondents agreed that having phishing-resistant MFA strategies have been crucial, lower than 20% had carried out any such process throughout their enterprises.
We used the next references that describe lots of the MFA exploits in additional technical element, and methods to forestall them, together with:
- A set of bypass strategies illustrated by Irregular Safety
- KnowBe4’s in depth slide deck detailing a lot of MFA exploit strategies, although considerably outdated
- The FIDO Alliance’s sequence of white papers on how enterprises can implement higher MFA strategies
- JumpCloud’s assortment of MFA utilization statistics from surveys
- Cisco Duo’s MFA Purchaser’s Information, which particulars methods to cost-justify stronger MFA deployments
- RSA’s helpful deep dive on implementing higher MFA packages through its passwordless options
Notable MFA menace modalities and customary assault strategies
The under desk gives an outline of 4 widespread MFA menace modalities, together with the related assault strategies utilized throughout particular areas.
Of word is that indisputable fact that attackers have discovered weaknesses throughout all features of enterprise computing infrastructure. A part of the issue is that the common fashionable authentication workflow is complicated: Customers can arrive at an utility through an online portal, a smartphone app, an AI question, or an API. They will join through quite a lot of endpoints, by way of a neighborhood community or a VPN, working completely different OSes and browsers. In consequence, any enterprise testing its MFA portfolio should apply cautious and continuous vigilance to a seize bag of circumstances and areas the place MFA codes might be intercepted.
MFA bypass and exploit applied sciences
| Strategies | Community | Cell | Functions | Workflow | Browser and cookie |
| Fatigue | Gaps in auth and entry insurance policies | Immediate bombing, Gaps in auth and entry insurance policies | Immediate bombing | Immediate bombing, Gaps in auth and entry insurance policies | Immediate bombing, Gaps in auth and entry insurance policies |
| Social Engineering | Evil proxy servers, Actual-time phishing relay | Vishing, SMS phishing, SIM swapping | Non MFA-enabled apps, Faked web sites, TOTP relay | Consent phishing, Account restoration abuses | Man-in-the-browser, Consent phishing |
| Stealing auth tokens/cookies | MITM assaults | Auth app phising | Malicious MFA software program | Session hijacking | Session hijacking, Move-the-cookie |
| Focusing on weak authentication | Manipulate trusted IPs/units | Reused passwords, Lack of FIDO/biometrics | Weak account restoration, Non-MFA accounts, IMAP/POP e-mail entry | Prior auth/logins, Brute power MFA | Session hijacking, Move-the-cookie, Man-in-the-browser, Consent phishing |
MFA fatigue
MFA fatigue is an assault modality that entails quickly sending quite a few authorization requests, sometimes through SMS push messages, till a person offers in and approves the request, granting entry to an attacker, comparable to what occurred to Uber in 2022.
That is certainly one of quite a few the reason why SMS has lengthy been thought of a really insecure second issue channel and why it nonetheless is a menace, as evidenced by PayPal’s 2026 elimination of MFA-based SMS.
These assaults additionally go by the identify “push bombing” or “immediate bombing” and usually are not restricted to cellular exploits. MFA fatigue can even reap the benefits of gaps in authentication or entry management insurance policies. The irony is that the extra MFA a company makes use of, the extra seemingly an MFA fatigue assault will succeed.
Social engineering
Attackers additionally use a mix of social engineering andphishing assaults — primarily based on SMS (smishing) or voice calls (vishing) to disrupt the general authentication workflow and trick customers into giving up MFA tokens.
Modifications in person conduct, comparable to extra distant post-pandemic utilization and occasions such because the World Cup, are sometimes exploited by dangerous actors. Arctic Wolf wrote in its weblog, “Utilizing social engineering together with an MFA fatigue assault might be efficient for menace actors, because it creates a false sense of belief.”
These mixture assaults additionally usually lure customers to pretend web sites, real-time phishing relays, or proxy servers to seize one-time passcodes. For cellular authenticators, SIM swaps will also be used to redirect one-time codes to an attacker’s cellphone. These occur by convincing a customer support worker at a telecommunications supplier that they’re the authentic cellphone proprietor after which use SMS to entry authentication messages.
Extra not too long ago we’ve seen exploits that use account restoration or password reset fallbacks to bypass MFA protections.
Stealing authentication cookies
Hijackers can even compromise MFA classes by stealing authentication cookies or different tokens. This may be completed in a number of methods, together with organising phony login pages, utilizing relays or man-in-the-middle or man-in-the-browser proxies to intercept and acquire the MFA codes.
A Joomla compromise from final 12 months supplies an instance. As a result of quite a few web sites don’t implement session inactivity closing dates, attackers might use endpoints that had acquired prior authentication and steal cookies to bypass MFA. “The authorization course of doesn’t have a means of figuring out whether or not the present holder of that entry management token was the authentic person or ever efficiently authenticated. This key reality is usually utilized by hackers to compromise MFA,” KnowBe4’s researchers wrote of their report.
Focusing on weak authentication
Focusing on non-MFA customers and purposes with weak passwords is one other widespread menace modality that may function throughout all the computing spectrum. Whereas MFA adoption has improved, it nonetheless is way from common, and attackers rely on discovering these unprotected locations and customers to focus on their efforts accordingly.
Just a few years in the past Akira ransomware menace actors infiltrated organizations utilizing Cisco VPNs that weren’t configured for MFA, the place they may use brute power to acquire person credentials. Going again to the 2021 Colonial Pipeline assault, analysts discovered it was brought on by compromising a single password used on a legacy VPN that wasn’t working any MFA.
Utilizing different service accounts that will have been as soon as utilized by directors or by customers who’ve both forgotten them or left the corporate are additionally a typical pathway for these kinds of compromises. There are additionally circumstances of making the most of already-authenticated IP addresses or units, or direct assaults on mobile networks, or organising proxy servers to intercept MFA codes.
Methods to cease MFA assaults
Given all these exploits, MFA wants consideration to element to make sure safety. Listed here are a couple of suggestions for guaranteeing your MFA technique will probably be profitable.
1. Perceive what you’re attempting to guard
First, safety groups should perceive the assets they search to guard from compromise. “For instance, cyber menace actors usually goal e-mail programs, file servers, and distant entry programs to realize entry to a company’s information, together with attempting to compromise id servers like Lively Listing, which might enable them to create new accounts or take management of person accounts,” based on this CISA reality sheet.
CISA recommends programs that help FIDO protocols for the primary recipients of MFA safety. This contains utilizing {hardware} keys, higher biometric controls, and organising passwordless entry for essentially the most delicate purposes.
CISA’s reality sheet got here out greater than three years in the past, and I really feel its suggestions don’t go far sufficient: Higher MFA ought to be enterprise huge.
Kevin Surace, CEO of biometric authentication supplier Token.com, tells CSO: “We moved to MFA, and [the attackers] moved with us.” Because of this enterprise safety managers should up their sport as nicely.
“There are some MFA strategies with out biometrics so it’s not as safe, because it doesn’t assure the particular person, simply possession,” Surace says. “Whereas it technically works brief time period, it’s not the top sport. We’ll all be given companies like Zoom and banking that may require actual stay biometrics to confirm id.”
One instance is when Microsoft launched conditional entry and risk-based authentication to fight superior MFA bypass strategies comparable to token theft and session hijacking, reflecting its ongoing efforts to strengthen id safety.
2. Get adaptive with authentication
Subsequent, all authentications ought to be real-time, steady risk-based assessments, and they need to dynamically step up safety necessities routinely primarily based on what customers are doing at any given second.
The outdated methods of utilizing a single entry management second when a person logs in must be changed accordingly. There are a variety of authentication merchandise that couple MFA into their adaptive authentication processes, and mix with the above hardened strategies, comparable to asking for a passwordless verification once you need to add a brand new payee in your checking account.
3. Button down entry rights
A companion effort ought to be a cautious evaluation and frequent evaluation of person and utility entry rights.
IT safety employees ought to guarantee workers solely obtain entry to restricted information wanted to perform their job tasks. However this isn’t all the time easy to perform, as roles and tasks change. Nonetheless, through the years it’s common to see quite a few customers who’re overprovisioned entry rights with none subsequent auditing or discount in these rights.
4. Conduct MFA workflow evaluation recurrently
All these factors ought to be a part of an general MFA workflow evaluation, which actually isn’t something new. Gerhard Giese from Akamai factors this out in a 2021 weblog publish, when he talks about how MFA doesn’t all the time forestall credential stuffing.
Giese says IT managers have to “re-examine your authentication workflows and login screens to verify an attacker can’t uncover legitimate credentials by interrogating the net server’s response and implement a bot administration resolution to ensure you do not make issues simpler for the dangerous guys.”
5. Assessment your password reset workflow
One facet that appears to get traditionally uncared for is the password reset workflow course of, which is why it’s a widespread goal of attackers.
“Surprisingly, there are lots of web sites that don’t have a second layer of verification for his or her 2FA reset password course of, or they provide MFA however don’t implement customers to make use of it,” says Mitnick Safety on this weblog publish. Having higher MFA, together with limits on unsuccessful login makes an attempt and password reuse can even assist.
6. Make sure the safety of high-value targets
Lastly, you must assess and find customers who may be high-value targets.
“Each group has a small variety of person accounts which have extra entry or privileges, that are particularly beneficial to cyber menace actors,” CISA writes in its report. Examples embody IT and system directors, employees attorneys, and HR managers. Take into account these teams for an preliminary rollout part of your MFA undertaking.
MFA know-how ought to be part of company safety’s crucial infrastructure. Latest assaults, in addition to urging from specialists throughout authorities and the personal sector, ought to present additional impetus for clever implementations.


