For years, security experts have recommended Multi-Factor Authentication (MFA) as one of the most important protections against stolen passwords.
- Something you have: A code generated by an authenticator app (like Microsoft Authenticator or Google Authenticator), a hardware security key (like a YubiKey), or an SMS/email verification code.
- Something you are: Biometrics like a fingerprint or facial recognition.
Why is it used?
That advice is still valid.
However, modern phishing attacks are becoming more sophisticated. Instead of simply stealing your password, attackers can attempt to steal the authenticated session created after you successfully complete MFA.
This changes an important part of the security equation:
The question is no longer only "Did the attacker steal my password?"
It can also be:
"Did the attacker steal my authenticated session?"
Recent campaigns targeting Microsoft 365 users demonstrate how this technique is being used in the wild.
A Recent Example: BigBear 2.0
In September 2026, researchers reported a phishing-as-a-service operation known as BigBear 2.0.
According to CloudSEK research reported by BleepingComputer, the operation targeted hundreds of organizations and collected thousands of Microsoft 365 credentials and session cookies.
The phishing infrastructure used an adversary-in-the-middle (AiTM) approach. Instead of sending the victim directly to a fake login page, the attack can place an attacker-controlled intermediary between the victim and the legitimate authentication service.
The victim may therefore see a login process that looks genuine.
The important difference is what happens behind the scenes.
The attacker attempts to capture authentication information—including the authenticated session—after the victim completes MFA.
How Does This Work?
A simplified version looks like this:
Traditional phishing:
Victim
↓
Fake login page
↓
Username + Password
↓
Attacker
With MFA enabled, the attacker may have a harder time using the stolen password by itself.
Modern AiTM phishing can instead look more like:
Victim
↓
Phishing website
↓
Attacker-controlled proxy
↓
Legitimate authentication service
↓
MFA challenge
↓
Victim approves MFA
↓
Authenticated session
↓
Attacker captures session information
The attacker is not necessarily "breaking" MFA cryptography.
Instead, the attack abuses the authentication process around the legitimate service.
Why Does MFA Still Matter?
This does not mean that MFA is useless.
MFA remains an important security control because it can prevent many attacks where criminals only possess a stolen password.
The problem is that security is rarely based on one protection.
An attacker who can manipulate the authentication process, steal session information, trick a victim into approving a malicious authentication request, or compromise the endpoint may be able to bypass protections that would stop a simple password attack.
This is why MFA should be combined with other security measures.
Another Growing Technique: Device-Code Phishing
Another technique receiving attention in 2026 involves device-code authentication.
Microsoft has reported phishing activity where attackers persuade victims to enter a code into Microsoft's legitimate authentication website.
The website itself may be genuine.
The problem is who requested the code and which device the authentication is authorizing.
In documented attacks, victims were persuaded to complete authentication and unintentionally authorize an attacker-controlled client. Microsoft reports that compromised tokens could then be replayed to access resources.
This is particularly dangerous because the victim may see a legitimate Microsoft website and believe everything is normal.
Don't Automatically Approve MFA Requests
One of the most important habits users can develop is simple:
If you didn't start the login, don't approve it.
If your phone suddenly displays:
"Approve sign-in?"
and you are not currently signing into an account, do not approve the request.
An unexpected MFA notification can be a warning that someone else is attempting to authenticate using your credentials.
Reject the request and investigate.
Watch Out for Unexpected Codes
Be careful when someone sends you instructions such as:
"Go to this website and enter the code I sent you."
or:
"This code is required to verify your account."
The code may not be verifying the thing you think it is.
It could potentially be authorizing a login or device controlled by someone else.
When authentication is involved, always ask:
Who initiated this authentication?
Which account am I authenticating?
Which device or application am I authorizing?
Phishing Pages Can Look Extremely Convincing
Modern phishing does not always look like the old scams with obvious spelling mistakes.
Attackers can reproduce:
Company logos
Login screens
Fonts
Colors
Error messages
Security notifications
Document-sharing pages
Microsoft 365 authentication workflows
Some campaigns also use legitimate services and infrastructure as part of the delivery process.
For example, Microsoft's recent reporting describes phishing campaigns abusing legitimate OAuth and device-code functionality rather than simply presenting an obvious fake login page.
Never Assume HTTPS Means "Safe"
A common misconception is:
"The website has HTTPS, so it must be legitimate."
Not necessarily.
HTTPS protects communication between your browser and the website.
It does not tell you whether the website operator is trustworthy.
A phishing website can also use HTTPS.
Therefore, don't use the padlock alone as proof that a website is legitimate.
Use the Official Application Whenever Possible
If you receive a message saying:
"Your Microsoft account needs verification."
Don't click the link immediately.
Instead:
Open your browser yourself.
Type the known official website address.
Sign in normally.
Check your account notifications.
Look for security alerts.
Investigate the request from inside the official service.
The same principle applies to:
Banks
Facebook
Google
Microsoft
Apple
PayPal
Online shopping accounts
Cryptocurrency services
Government websites
Don't let the message choose the website for you.
What About Passkeys?
Passkeys are designed to provide stronger protection against traditional phishing attacks.
However, recent security research has also examined weaknesses in the systems surrounding passkeys—including operating systems, browsers, cloud synchronization, authentication flows, and compromised endpoints.
The important distinction is that these research findings do not mean that the underlying FIDO2/WebAuthn cryptography has been broken.
Instead, they demonstrate that authentication security depends on the entire system around the credential.
This leads to an important security principle:
Strong authentication cannot completely compensate for a compromised device or a compromised authentication process.
Protect the Device, Not Just the Account
Account security and device security are connected.
If malware is already running on your computer or phone, an attacker may be able to interact with browsers, authentication applications, files, or other information available to the user.
For this reason, keep your devices updated and protected.
On Windows:
Install security updates.
Keep Microsoft Defender or another reputable security product enabled.
Remove suspicious browser extensions.
Don't install pirated software.
Avoid unknown executables.
Use a standard user account where practical.
Review unfamiliar applications.
Keep browsers updated.
On Android:
Install applications from trusted sources.
Avoid installing APK files from unknown websites.
Be suspicious of apps requesting Accessibility permissions.
Don't enable Developer Options or Wireless Debugging because an unknown app tells you to.
Keep Android and applications updated.
Recent research into the Android Trojan RatHat, for example, found malware abusing Accessibility features and Wireless Debugging while using AI-assisted interaction to navigate an infected device.
If You Think Your Account Was Phished
Act quickly.
1. Change the password
Use the legitimate website or official application.
Do not use the link from the suspicious message.
2. Check active sessions
Look for:
Unknown devices
Unknown locations
Suspicious browsers
Recent login activity
Sign out unfamiliar sessions.
3. Check MFA settings
Look for unfamiliar:
Authenticator applications
Phone numbers
Security keys
Recovery methods
Attackers may attempt to add their own authentication method after gaining access.
Microsoft has documented cases where attackers registered their own MFA method to maintain persistence inside compromised accounts.
4. Check email forwarding rules
For compromised email accounts, examine forwarding and mailbox rules.
An attacker may create rules that automatically forward messages or hide security notifications.
5. Check connected applications
Review third-party applications that have access to your account.
Remove anything you don't recognize.
6. Contact your organization or service provider
If the account belongs to your workplace, school, bank, or another organization, report the incident immediately.
The New Security Rule
The traditional security advice was:
Don't give your password to anyone.
That advice is still important.
But modern phishing requires a broader rule:
Don't authenticate something you didn't intentionally initiate.
Don't approve unexpected MFA requests.
Don't enter authentication codes because someone told you to.
Don't authorize unfamiliar devices.
Don't install software because a webpage says your computer is infected.
Don't give remote access to strangers.
And don't assume a website is legitimate simply because it looks professional.
A Simple Phishing Defense Checklist
Before responding to an unexpected security message, stop and ask:
☐ Did I initiate this login?
☐ Do I recognize the website?
☐ Does the domain actually belong to the organization?
☐ Is someone pressuring me to act immediately?
☐ Am I being asked to enter an authentication code?
☐ Am I being asked to approve an MFA request?
☐ Am I being asked to install software?
☐ Am I being asked to enable Accessibility or remote access?
☐ Can I verify the request through the official application?
If the answer to any of these raises suspicion:
Stop. Don't click. Verify first.
Final Thoughts
The security landscape is changing.
Attackers don't always need to "break into" an account in the traditional sense. Increasingly, they try to convince the legitimate user to authenticate for them or attempt to steal the session created by a legitimate authentication process.
MFA remains an important layer of protection. Passkeys and other phishing-resistant authentication technologies can also provide stronger defenses against many traditional attacks.
But no single security technology should be treated as a magic shield.
The strongest defense combines:
Good authentication + updated devices + security software + careful verification + user awareness.
When something asks you to log in, approve a request, enter a code, install software, or provide sensitive information:
Stop for a moment.
Verify the request.
Then decide.
That few-second pause may be one of your most valuable security tools.
Comments
Post a Comment
Please feel free to write your comments.