Posted in

Why Traditional MFA No Longer Stops Every Phishing Attack

MFA

A finance manager opens a convincing Microsoft 365 link, enters her password, and approves an MFA prompt. Minutes later, an attacker is reading her inbox through a session.

The Attack That Does Not Need to Defeat MFA

This technique is known as adversary-in-the-middle, or AiTM, phishing. Microsoft reported a 146% year-over-year rise in AiTM attacks in its 2024 Digital Defense Report. Cisco Talos observed MFA-related weaknesses in nearly half of its incident-response engagements during the first quarter of 2024. These included several weaknesses, not AiTM alone.

Phishing-as-a-service tools have lowered the barrier to relaying credentials, MFA responses, and authenticated sessions. Defenses need a phishing-resistant MFA solution designed to prevent authentication responses from being relayed to a fraudulent domain.

How an AiTM Attack Works

An AiTM attack places a reverse proxy between the victim and the legitimate identity provider. The proxy relays the real sign-in process, including the password and MFA challenge, while capturing the session cookie or token returned after authentication. If that artifact can be reused, the attacker may enter the account without repeating MFA.

An overview at hideez.com explains how cryptographic authentication can fit into an identity strategy.

FIDO2 and WebAuthn generate a cryptographic response for the legitimate service’s domain. A fraudulent site cannot request a valid response for another domain, leaving an AiTM proxy with nothing usable to relay.

Why Push Notifications and One-Time Codes Fall Short

SMS codes, authenticator-generated codes, and basic push approvals improve security over passwords alone, but they are not cryptographically bound to the legitimate website. A code can be entered into a proxy, while a push request can be approved after the attacker initiates a login attempt.

Number matching and contextual details make push-based attacks harder, but they do not provide the same phishing resistance as origin-bound authentication. Repeated prompts may also lead users to approve a request too quickly.

What Phishing-Resistant Authentication Changes

A properly configured security key or passkey verifies the relying party before creating an authentication response. On a lookalike domain, the authenticator will not produce a valid response for the legitimate service. CISA identifies FIDO/WebAuthn as a widely available phishing-resistant option, while NIST recognizes verifier name binding as a method of phishing resistance.

Moving high-risk accounts and administrators to phishing-resistant authentication reduces exposure to credential-relay attacks. It does not prevent every form of session theft: malware, compromised endpoints, and stolen tokens still require other controls. A convincing login page and an approved MFA prompt are no longer enough to complete an AiTM attack.

Leave a Reply

Your email address will not be published. Required fields are marked *