All resources Resources

The phishing attack that walks straight past your MFA

You click a link, type your password, approve the prompt on your phone, and carry on with your day. Everything worked exactly the way it always does. What you don't see is that someone else just logged into your account at the same moment, using the exact login you just completed.

That's unsettling, especially if you've already turned on multi-factor authentication and assumed it had you covered. This is a newer style of attack called adversary-in-the-middle, and it's built specifically to slip past the protection most businesses rely on. Here's what it is, why your second step on your phone doesn't stop it, and what we put in place for clients across the Denver area to keep it out.

Phishing isn't really after your password anymore

For years, the goal of a phishing email was simple: trick you into typing your username and password so the attacker could use them later. Multi-factor authentication, the tap-to-approve or one-time code that proves it's really you, made that stolen password much less useful on its own. So the attackers changed targets.

Instead of collecting your password to use later, modern phishing intercepts your login as it's happening and steals the thing that proves you've already signed in. Once you've passed your second step, the attacker doesn't need your password or your phone again. They just step into the session you opened.

What's made this dangerous is how easy it's become. There are now off-the-shelf kits that let even low-skill criminals run these campaigns at scale against Microsoft 365 and Google Workspace accounts. You don't have to be a high-value target to get caught.

How the attack actually works

The fake login page that isn't quite fake

The fraudulent page in this kind of attack isn't a crude copy. It sits invisibly between you and the real Microsoft or Google sign-in, quietly passing everything you type through to the genuine service and passing the real responses back to you. From your side, nothing looks off: the branding is right, the page works, and the authentication prompt on your phone arrives exactly as expected.

The only tell is usually the web address: a slightly wrong domain that's easy to miss on a phone screen or when you're rushing between tasks.

Why the second step doesn't save you

Multi-factor authentication protects the moment you log in. It doesn't protect what happens right after. Once you've successfully signed in, the service hands your browser a small file, a session token, that quietly tells the app, "this person is already verified, let them through." For the rest of that session, no password or phone prompt is required.

The attack simply waits for that token to be issued, grabs a copy of it, and loads it into their own browser. To Microsoft or Google, they look exactly like you, already logged in. Microsoft has tracked a roughly 146% jump in these attacks over the past year, precisely because they target the accounts MFA was supposed to have locked down.

Why you might not notice for weeks

The quiet part is what makes this so damaging. The attacker is sitting inside a real, verified session, so there are no failed logins, no strange alerts, and nothing in the usual sign-in records to wave a flag. Researchers who've studied these break-ins find the intruder typically settles in: creating hidden inbox rules that secretly forward your mail, registering their own phone as a second factor so they keep getting back in, and watching email threads for conversations about money.

That's why these attacks are so often discovered late, only after a fraudulent payment has gone out or the same trusted account has been used to phish your coworkers and customers.

How we lower your risk

Multi-factor authentication is still essential: it's the right starting point, and we'd never tell a client to turn it off. But stopping this particular attack takes a few more layers beyond the login screen itself.

Use phishing-resistant sign-in

Some sign-in methods can't be relayed through a fake page at all. Hardware security keys and passkeys, credentials tied to your specific device and the real web address, simply refuse to work if the page isn't genuinely Microsoft or Google. The attacker's middle-man page breaks the process instead of stealing it. Canada's national cyber centre studied more than 100 of these campaigns and found that phishing-resistant sign-in consistently blocked the theft where ordinary push prompts and one-time codes did not. If you're curious how this works in practice, we walk through it in our guide to moving your team to passkeys.

Tighten the rules around who can sign in

We can set conditions on access so that logins from unfamiliar locations or unmanaged devices face extra scrutiny, and so that suspicious activity after login, like a new forwarding rule or a phone added at 2 a.m., gets flagged for review. Sign-in logs alone won't surface this kind of attack; you have to watch what happens once someone is inside.

Help your team recognize the lure

A short, plain-English walkthrough goes a long way. Once people understand that a working sign-in prompt on a slightly-off page is still a trap, they're far more likely to pause, check the address, and report it before a session gets hijacked.

Stop guarding only the front door

Multi-factor authentication is a baseline, not a finish line. The businesses that stay ahead of this are the ones that protect every layer: the login, the session, and what happens after, not just the password box. That's the kind of review we do for companies across the Denver area, in plain English and without the scare tactics.

If you'd like a second set of eyes on where your accounts stand today, a free IT check-up is an easy place to start.

Confident your logins can't be hijacked?

Book a free IT check-up and we'll review your sign-in security and tell you, in plain English, where you're exposed and what we'd shore up first.

Get started