Microsoft 365CIO BriefingsRetrospectives

CIO Brief: Why Standard MFA No Longer Stops Phishing

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by stealing the login session itself. The user did everything right — typed their password, approved the MFA prompt — and the attacker still got in.

Why standard MFA isn't enough anymore

Most MFA methods — text codes, app approvals, one-time codes — can be relayed by a fake website that sits between the user and Microsoft. Phishing kits that do this are cheap and widely available. Attackers use the stolen session to read email and redirect payments.

The business impact

  • Business email compromise and payment fraud.
  • False confidence — leadership believes MFA solved the problem.
  • Insurance implications as insurers ask about phishing-resistant MFA.

What does stop it

  • Phishing-resistant sign-in (passkeys, security keys, Windows Hello) that only works on the real website.
  • Requiring company-managed devices for access to email and files, so a stolen session can't be used elsewhere.

Questions to ask your team

  • What share of our users use phishing-resistant sign-in?
  • Can someone access our email from any computer with just a username, password and MFA approval?
  • Do our finance staff have extra protection?

What good looks like

Phishing-resistant MFA for admins and finance at minimum, managed-device requirements for sensitive data, and a plan to extend both to everyone.

The decision

Prioritize phishing-resistant MFA for finance, executives and administrators this quarter. These are the users phishing kits target most.

aitm phishing impactAiTM phishing campaign2022

More on this story