Talk to us about your IT support Real people · no obligation
Cyber Security

MFA Is Not Enough Any More: How Attackers Get Past It

29 July 2026 ·7 min read
MFA Is Not Enough Any More: How Attackers Get Past It

For years the advice was simple and it worked: turn on multi-factor authentication and you stop the overwhelming majority of account takeovers. That advice is still worth following. But treating MFA as the finish line is now a mistake, because the people attacking your accounts adapted some time ago.

If your security position is “we have MFA, we are fine”, this is the article to read properly.

How attackers get past it

Session hijacking, the big one. The attacker puts a proxy between you and the real login page. You receive a link, the page looks correct because it is relaying the genuine site, and you sign in — password, MFA prompt, everything. It all works, because it really is the real service behind the scenes.

What the attacker captures is not your password. It is the session cookie the service issues once you have successfully authenticated. That cookie is the proof you already passed MFA. Replayed into their own browser, it grants access without any prompt at all, because as far as the service is concerned the check already happened.

This is why “I completed the MFA prompt, so it must have been legitimate” is no longer sound reasoning.

MFA fatigue. The attacker has the password and simply requests approval over and over, often late at night. Eventually someone taps approve to stop their phone buzzing. Simple, and it still works.

Attacks on the recovery route. Why fight the front door when the side door is a phone call? A convincing call to a helpdesk asking to reset MFA for a locked-out employee bypasses the technology entirely.

SIM swapping. If your second factor is an SMS code, control of the phone number is control of the account.

What actually helps

Move to phishing-resistant methods. Passkeys and hardware security keys are bound to the real web address and will not authenticate against a lookalike domain. This is the single most effective change available, which is why it is worth prioritising for administrators and finance even if you cannot do it for everyone at once.

Turn off SMS as a factor where you can. It is meaningfully weaker than the alternatives. An authenticator app is better; a passkey or hardware key is better still.

Switch on number matching. Instead of a plain approve button, the user types a number shown on screen. It kills MFA fatigue, because you cannot approve a prompt you did not trigger without seeing the screen that raised it.

Shorten session lifetimes for sensitive accounts and re-check on risk. If a stolen session cookie expires quickly, its value drops. Conditional access rules that force re-authentication when a sign-in appears from an unfamiliar location or device close much of the gap.

Harden your helpdesk process. Decide now how you verify identity before resetting anyone’s MFA, and make it something an outsider cannot satisfy. This is a process fix, not a technology one, and it is very often the weakest link.

Tell your team what a real attack looks like now. Awareness training that only covers spelling mistakes and dodgy links is out of date. People need to know that a login page can look perfect, work correctly, and still be hostile.

The bottom line

MFA is still essential and you should absolutely keep it on. But it is a floor, not a ceiling. The meaningful next steps are phishing-resistant sign-in for the accounts that matter most, number matching to kill fatigue attacks, sensible session controls, and a helpdesk identity process that an attacker cannot talk their way through.

FAQ

Should we turn MFA off if it can be bypassed? Absolutely not. It still blocks the overwhelming majority of automated attacks. The point is to strengthen it, not abandon it.

Is an authenticator app good enough? It is a clear improvement on SMS and fine for most staff. For administrators, finance, and anyone who can authorise payments, aim for passkeys or hardware keys.

How would we know if a session had been hijacked? Look for sign-ins from unexpected locations, new mail forwarding rules, or unfamiliar registered devices. Those are the usual first signs, which is why someone reviewing sign-in alerts matters as much as the controls themselves.

Move forward with confidence

Book a free, no-obligation assessment. We’ll take a proper look at your setup and tell you plainly what’s working and what isn’t.