CIO Brief: Why Standard MFA No Longer Stops Phishing
Retrospective: this article looks back at events from July 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, Microsoft reported a phishing campaign that hit more than 10,000 organizations and got past multi-factor authentication by stealing the login session itself. The user did everything right — typed their password, approved the MFA prompt — and the attacker still got in.
Why standard MFA isn't enough anymore
Most MFA methods — text codes, app approvals, one-time codes — can be relayed by a fake website that sits between the user and Microsoft. Phishing kits that do this are cheap and widely available. Attackers use the stolen session to read email and redirect payments.
The business impact
- Business email compromise and payment fraud.
- False confidence — leadership believes MFA solved the problem.
- Insurance implications as insurers ask about phishing-resistant MFA.
What does stop it
- Phishing-resistant sign-in (passkeys, security keys, Windows Hello) that only works on the real website.
- Requiring company-managed devices for access to email and files, so a stolen session can't be used elsewhere.
Questions to ask your team
- What share of our users use phishing-resistant sign-in?
- Can someone access our email from any computer with just a username, password and MFA approval?
- Do our finance staff have extra protection?
What good looks like
Phishing-resistant MFA for admins and finance at minimum, managed-device requirements for sensitive data, and a plan to extend both to everyone.
The decision
Prioritize phishing-resistant MFA for finance, executives and administrators this quarter. These are the users phishing kits target most.
- Adversary-in-the-Middle Phishing Hits 10,000 Organizations (July 2022): MFA Bypassed at Scale Incident Teardowns
- How to Defeat AiTM Phishing With Compliant-Device and Phishing-Resistant MFA Policies How-To & Hardening
- Detecting AiTM Session Cookie Theft: Defender XDR and Sentinel Hunting Queries Detection & Response