• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Free Consultation
1300 887 889

PowerbITs

Making Technology Work For You

  • About
  • Managed IT Services
    • Network Security
    • Backup
    • Office Relocation
    • Mobile Device Management
  • Cyber Security
  • Business Process Automation
  • Contact

Phishing in Disguise: Why MFA Is No Longer Enough

Posted on July 31, 2026

For years, the advice has been simple: enable multi-factor authentication (MFA) and your business will be far better protected against cyber attacks.

While that advice is still true, it no longer tells the whole story. Today’s attackers aren’t always trying to steal passwords or bypass MFA.

They’re finding new ways to hijack authenticated sessions after users have already logged in.

That shift has changed the rules of phishing and account security, making traditional authentication alone insufficient for many modern threats.

Keep reading to discover how these attacks work, why they’re becoming more common, and the practical steps your business can take to stay protected.

MFA Still Works But Basic MFA Has a Blind Spot

Let’s be clear: multi-factor authentication (MFA) is still one of the most effective security controls any business can enable.

It stops countless attacks every day and remains an essential layer of defence.

The problem isn’t that MFA has stopped working; it’s that cyber criminals have changed how they attack. Instead of trying to beat MFA, they’re increasingly finding ways to work around it.

What Basic MFA Protects Against

  • Stolen passwords from phishing, breaches, and reused credentials.
  • Credential stuffing using passwords leaked from previous data breaches.
  • Simple brute-force attacks target weak or predictable passwords.
  • Unauthorised logins using exposed or compromised account credentials.

What Basic MFA Does Not Always Stop

  • Real-time phishing proxies capturing authenticated user sessions.
  • Session token theft after successful password and MFA verification.
  • Malicious browser extensions are stealing cookies and session data.
  • Infostealers, OAuth phishing, and manipulated MFA approval requests.

That’s the key difference many businesses miss.

Basic MFA proves a user has successfully completed the sign-in process, but it doesn’t always guarantee the session remains secure afterwards.

Modern phishing attacks are designed to target what happens after authentication, making phishing-resistant MFA and additional security controls just as important as turning MFA on in the first place.

The Real Threat Is Session Token Theft

If attackers are no longer focusing on passwords, what are they after instead? Increasingly, the answer is session tokens.

These small pieces of data are created after you’ve successfully signed in and completed MFA, allowing you to move between apps without constantly logging in again.

They make cloud services convenient, but in the wrong hands, they can also become one of the most valuable assets an attacker can steal.

What Is a Session Token?

  • A temporary digital pass proving you’ve already authenticated successfully.
  • Keeps users signed into Microsoft 365 and Google Workspace.
  • Allows seamless access across Outlook, Teams, SharePoint, and OneDrive.
  • Eliminates repeated password and MFA prompts during normal work.

Why Attackers Want Session Tokens

  • Stolen tokens let attackers impersonate legitimate authenticated users.
  • Passwords and new MFA approvals may become unnecessary.
  • Access appears legitimate because authentication already occurred.
  • Security systems may initially trust the stolen session.

Think of it this way: a password gets you to the front desk, while MFA confirms your identity before you’re allowed inside.

A session token is the visitor badge that lets you keep moving through the building without being stopped at every door.

If someone steals that badge, they don’t need to prove who they are again; they simply walk around as if they belong.

That’s why protecting session tokens has become just as important as protecting passwords themselves.

How Modern Phishing Bypasses MFA

Understanding why session tokens are valuable naturally leads to the next question: how do attackers actually steal them?

In most cases, they don’t hack Microsoft or Google directly. Instead, they trick users into handing over an authenticated session without ever realising it.

Adversary-in-the-Middle Phishing

One of the most effective techniques is called adversary-in-the-middle phishing.

An employee clicks a convincing email, Teams message, or shared-file link, signs in through a fake login page, approves the genuine MFA prompt, and unknowingly hands the attacker the newly issued session token.

Why This Feels Normal to the Employee

The attack succeeds because nothing appears unusual during the sign-in process.

The login page looks genuine, the MFA request is legitimate, and the employee still reaches Outlook or Google Workspace exactly as expected without any obvious warning signs.

Why Traditional Alerts May Miss It

Unlike failed login attempts or password guessing attacks, this activity often appears legitimate.

The password is correct, MFA is successfully completed, and the session has already been authorised, leaving unusual locations, devices, or user behaviour as the first meaningful indicators.

By now, it’s clear that fake login pages are a serious threat.

But they’re only one piece of a much bigger picture, because attackers have several other ways to steal authenticated sessions without ever asking you to log in to a fake website.

Attackers Do Not Always Need a Fake Login Page

While adversary-in-the-middle phishing receives most of the attention, it isn’t the only way attackers steal authenticated access.

In many cases, the compromise happens directly on the employee’s device or through legitimate authentication workflows that users trust without hesitation.

Malicious Browser Extensions

Employees often install browser extensions for screenshots, PDFs, grammar checks, coupons or tab management without thinking twice.

If an extension is malicious or later becomes compromised, broad browser permissions may allow it to access cookies, browser data, and even active session information.

Infostealer Malware

Infostealer malware often arrives through cracked software, fake updates, malicious downloads, or email attachments disguised as legitimate files.

Once installed, it quietly harvests saved passwords, browser cookies, and session tokens before selling that access to other cyber criminals.

Device-Code and OAuth Phishing

Not every phishing attack relies on a fake login page.

Some abuse legitimate Microsoft authentication processes by tricking users into entering a device code or approving an OAuth request, giving attackers authorised access without ever stealing the password itself.

The common thread across all of these attacks is that they target access, not just passwords.

And once attackers gain access to a business account, the consequences can extend far beyond a single employee or inbox.

Why Businesses Should Pay Attention

As businesses continue moving more operations to the cloud, attackers are changing what they target.

Today, compromising a single business account can provide access to far more than just email, making identity security more important than ever.

Cloud Accounts Now Hold the Keys to the Business

Business accounts are no longer limited to email and calendars.

They often provide access to the tools employees rely on every day, making a single compromised account far more valuable than many organisations realise.

  • Microsoft 365 and Google Workspace store daily business communications.
  • Xero, MYOB, and payroll platforms hold sensitive financial information.
  • CRMs and cloud storage contain valuable customer and business data.
  • Remote access tools connect users directly to critical systems.

The more services connected to one identity, the greater the potential impact of a breach. Protecting business accounts now means protecting the entire organisation.

A Single Compromised Mailbox Can Lead to Bigger Damage

A stolen mailbox is often just the beginning rather than the end of an attack.

Once inside, cyber criminals look for opportunities to expand access, impersonate trusted staff, and increase the financial impact.

  • Invoice fraud targets customers, suppliers, and finance departments.
  • Business email compromise enables trusted internal impersonation attacks.
  • Password resets unlock additional business systems and applications.
  • Stolen access creates pathways for ransomware and data theft.

What starts with one compromised account can quickly affect multiple systems across the business. The longer attackers remain unnoticed, the greater the potential financial and operational damage.

Small Businesses Are Not Too Small to Be Targeted

Many smaller organisations assume cyber criminals only focus on large enterprises with deeper pockets.

In reality, modern phishing campaigns are highly automated, allowing attackers to target thousands of businesses simultaneously with very little effort.

  • Automated attacks target thousands of businesses at the same time.
  • Smaller organisations often have fewer dedicated security resources.
  • One successful compromise can deliver immediate financial returns.
  • Attackers prioritise easy opportunities over business size.

Being a smaller business doesn’t make you less visible to attackers. In many cases, it simply makes you a more attractive target because they expect fewer security controls to stand in their way.

The encouraging news is that businesses don’t need to accept this risk as the new normal.

By upgrading the way users authenticate, organisations can shut down many of the techniques that modern phishing attacks rely on before they ever succeed.

The Better Defence Is Phishing-Resistant MFA

If attackers have evolved beyond traditional phishing, your authentication strategy needs to evolve too.

The goal is no longer just verifying who signs in, but ensuring that authentication can’t be intercepted, replayed, or abused by someone else.

What Phishing-Resistant MFA Means

Phishing-resistant MFA is designed to prevent attackers from capturing and reusing authentication credentials.

It verifies that users are signing in to the genuine website or application, eliminating authentication codes that can be copied, relayed, or manipulated through fake login pages.

Passkeys

Passkeys replace passwords with cryptographic credentials stored securely on a trusted device.

They work only with the legitimate website or application, making them resistant to phishing while providing a faster and simpler sign-in experience for employees.

FIDO2 Security Keys

FIDO2 security keys are physical authentication devices that require users to verify their identity directly on the device.

They provide strong protection for administrators, finance teams and other high-risk users with access to sensitive business systems.

Windows Hello for Business

For organisations using Microsoft environments, Windows Hello for Business provides phishing-resistant authentication using the device, together with a PIN or biometrics.

It offers significantly stronger protection than passwords combined with SMS codes or traditional authenticator methods.

The best place to begin isn’t with every employee at once.

Prioritise administrators, finance teams, payroll staff, executives, and anyone with access to sensitive business data, then expand phishing-resistant MFA across the rest of the organisation.

Conditional Access Stops Stolen Sessions from Being Used Anywhere

Phishing-resistant MFA is a major step forward, but it shouldn’t work alone.

Even if an attacker somehow obtains a valid session, additional controls can determine whether that session should be trusted based on the context surrounding every sign-in.

What Conditional Access Does

Conditional Access adds intelligence to every authentication decision instead of simply checking whether a password and MFA were correct.

It evaluates the surrounding context before allowing access to business resources.

  • Verifies user, device, location, and sign-in risk together.
  • Restricts access from unmanaged or unknown devices automatically.
  • Applies different rules for apps and user groups.
  • Continuously evaluates sessions beyond the initial login process.

Rather than trusting every successful login equally, Conditional Access continuously asks whether that session still looks legitimate.

This makes stolen sessions much harder for attackers to use successfully.

Practical Rules Businesses Should Consider

The most effective Conditional Access policies focus on reducing unnecessary risk without disrupting legitimate work.

Small changes to authentication rules can significantly reduce the chances of a stolen session being abused.

  • Block sign-ins from countries your business never operates.
  • Require compliant devices for accessing sensitive business applications.
  • Enforce stronger authentication for administrators and privileged accounts.
  • Monitor risky sessions and impossible travel sign-in patterns.

These policies don’t replace MFA.

They strengthen it by adding context to every access request. The result is better protection without creating unnecessary friction for everyday users.

Google Workspace Equivalent

Businesses using Google Workspace have access to similar capabilities through Context-Aware Access.

These controls evaluate device trust, user location, and application context before granting access to Google services.

  • Apply device and location-based access control policies.
  • Protect Gmail, Drive, and other Google Workspace services.
  • Restrict access from unmanaged or high-risk devices.
  • Enforce different policies for users and applications.

Whether you’re using Microsoft 365 or Google Workspace, the objective remains the same. Every access request should be evaluated on more than just a successful password and MFA challenge.

Even the smartest authentication policies have one important limitation: they can only protect the sign-in process.

If the device itself is compromised, attackers may bypass those protections by stealing authenticated sessions directly from the user’s browser.

Browser and Device Security Matter More Than Ever

Strong authentication is only one part of the security equation.

If an attacker compromises the browser or device being used, they may be able to steal session tokens directly without interfering with the login process.

That’s why endpoint and browser security have become essential layers of defence against modern phishing attacks.

  • Restrict browser extensions to an approved business whitelist only.
  • Remove unused extensions and review permissions regularly.
  • Keep browsers, endpoints, and operating systems fully updated.
  • Prioritise stronger protection for high-risk users and devices.

Modern endpoint protection, browser controls, and disciplined software management make it significantly harder for attackers to capture session tokens from compromised devices.

Equally important is protecting your highest-risk users first, including directors, finance teams, payroll staff, HR personnel, IT administrators, and anyone with access to sensitive client information or payment systems.

When strong authentication is backed by secure browsers and well-managed endpoints, businesses dramatically reduce the number of opportunities attackers have to gain and maintain unauthorised access.

What To Do If You Suspect Token Theft

The sooner you respond to suspected token theft, the better your chances of limiting the damage.

Because attackers often use valid sessions rather than stolen passwords, unusual account behaviour is usually the first warning.

Acting quickly can prevent a single compromised account from escalating into a much larger security incident.

  • Watch for unusual inbox or email forwarding rules.
  • Investigate logins from unfamiliar devices or unexpected locations.
  • Check unrecognised sent emails and unusual file activity.
  • Review unexpected password resets and unsolicited MFA prompts.
  • Revoke active sessions and reset affected account passwords.
  • Remove suspicious app permissions and scan affected devices.
  • Document the incident and notify affected stakeholders promptly.

One important point is that changing a password alone may not be enough.

If a stolen session token or authorised OAuth permission remains active, attackers may still retain access even after the password has been reset.

That’s why every response should include revoking active sessions, reviewing application permissions, checking recent sign-in activity, and isolating compromised devices where necessary.

A complete response removes the attacker’s access, not just the original password they may have used.

A Practical MFA Upgrade Plan for Your Business

By this point, the path forward should be clear.

Reducing the risk of token theft doesn’t require a complete technology overhaul, it requires a structured approach that strengthens authentication, devices, and user awareness one step at a time.

Step 1: Audit Current MFA Methods

Before making changes, understand what authentication methods your organisation currently relies on. A clear assessment will highlight weak points and help prioritise the upgrades that matter most.

  • Identify users still relying on SMS verification.
  • Review authenticator app usage across all employees.
  • Confirm privileged accounts have MFA enabled consistently.
  • Document single sign-on and break-glass account access.

A thorough audit creates the foundation for every improvement that follows. You can’t strengthen what you haven’t measured.

Step 2: Remove the Weakest Methods

Not all MFA methods provide the same level of protection against modern phishing attacks.

Replacing the weakest options immediately reduces opportunities for attackers to intercept or manipulate authentication.

  • Phase out SMS verification wherever practical.
  • Remove voice call and email authentication methods.
  • Eliminate uncontrolled push approval notifications completely.
  • Standardise stronger authentication across business accounts.

Reducing reliance on weaker methods closes common attack paths. The fewer phishable authentication methods available, the better.

Step 3: Roll Out Phishing-Resistant MFA

Once weaker methods are removed, introduce phishing-resistant authentication in stages rather than all at once.

Prioritising the highest-risk users delivers the greatest security benefit with minimal disruption.

  • Protect administrators before standard employee accounts.
  • Prioritise finance, payroll, and executive teams next.
  • Extend protection to remote and hybrid workers.
  • Roll out organisation-wide after high-risk users.

Start where the business impact is greatest if a compromise occurs. High-value accounts deserve the strongest protection first.

Step 4: Enable Conditional Access Controls

Strong authentication becomes even more effective when combined with contextual access decisions. Begin with low-risk policies in report-only mode before gradually enforcing them across the organisation.

  • Block access from unexpected countries or locations.
  • Require compliant and managed business devices.
  • Apply stricter policies to privileged administrator accounts.
  • Review risky sign-ins before enforcing stricter policies.

Rolling out policies gradually reduces disruption while improving security. It also gives teams time to adjust before full enforcement.

Step 5: Secure Browsers and Endpoints

Authentication alone cannot protect compromised devices from token theft.

Establishing a consistent security baseline across browsers and endpoints reduces the opportunities attackers have to steal authenticated sessions.

  • Restrict browser extensions to approved business tools.
  • Keep browsers and operating systems fully updated.
  • Block unknown software from business devices.
  • Limit local administrator privileges wherever possible.

A secure endpoint strengthens every other security control around it. Protecting devices means protecting authenticated users as well.

Step 6: Train Staff for Modern Phishing

Technology alone cannot stop every attack without informed users.

Employees need to recognise how phishing has evolved beyond fake passwords and suspicious email attachments.

  • Recognise fake login pages and QR-code phishing.
  • Question unexpected MFA prompts before approving requests.
  • Understand device-code and OAuth phishing techniques.
  • Report suspicious shared-document links immediately.

The best security tools are supported by informed employees. Regular awareness training helps turn users into another layer of defence instead of the weakest link.

Final Thoughts: MFA Is the Starting Point, Not the Finish Line

The way cyber criminals compromise business accounts has changed, and businesses need to change with it.

While MFA remains an essential security control, it is no longer enough on its own to stop modern phishing attacks that target authenticated sessions instead of passwords.

By combining phishing-resistant MFA, Conditional Access, secure browsers, protected endpoints, and ongoing staff awareness, businesses can dramatically reduce the risk of account takeover and the costly disruption that often follows.

Modern cyber security isn’t about trusting every successful login; it’s about continuously verifying that access should still be trusted.

Not sure whether your business is protected against modern phishing attacks?

PowerbITs can assess your current security posture and help you implement the right protections before attackers find the gaps.

Filed Under: Email, IT Managed Services, IT Support, Network Security, OneDrive, Security, Sharepoint, Teams Tagged With: Antivirus, business safety, cybersecurity, Email, IT Help Desk, IT Helpdesk, IT Managed Services, Malware, network security, network support, OneDrive, Ransomare, Ransomware, Risk Management, Security, sharepoint, Teams

Primary Sidebar

Recent Posts

Phishing in Disguise: Why MFA Is No Longer Enough

How to Protect Your Business from AI-Powered Phishing

Why So Many AI Projects Fail to Scale (And How to Fix It)

How Dr Mark Modernised an Ageing Clinical DVD Archive

ChatGPT Extensions Can Be Risky: Here’s What to Know

Footer

Menu

  • About
  • IT Service Plan
  • Managed IT Services
  • Cyber Security
  • Backup
  • Office Relocation
  • Mobile Device Management
  • How It Works
  • Blog
  • Contact

Contact Us

1300 887 889
Suite 201,
14-16 Suakin Street,
Pymble,
NSW 2073

How to Keep Your Data Secure

  • This field is for validation purposes and should be left unchanged.
  • Get the seven things you must do to keep your business data secure...

© 2019 PowerbITs | Website by Website Love