← research
Public-source retrospective15 February 2026Checked 11 October 20265 min read

MFA Did Not End Phishing. It Moved the Target

A session-focused reading of adversary-in-the-middle phishing, why the phrase MFA bypass is imprecise, and where phishing-resistant authentication helps.

Identity securityPhishingAuthentication
An authenticated session crossing a hostile relay between a user and service
An authenticated session crossing a hostile relay between a user and service. Editorial illustration.

Calling every successful phishing attempt an “MFA bypass” hides the part defenders actually need to see.

In February I revisited adversary-in-the-middle phishing because the usual description felt too vague. A victim can complete a legitimate authentication challenge while an attacker relays the exchange and captures the resulting session. The factor was not necessarily broken. The session became the target.

Question

What does adversary-in-the-middle phishing defeat, what does it leave intact, and why does that distinction change the defensive plan?

Method

I compared Microsoft’s incident analysis with CISA’s guidance on phishing-resistant MFA and the FIDO Alliance’s deployment model for passkeys. I focused on the trust transitions: credential entry, factor completion, origin binding, session issuance, and account recovery.

I avoided reproducing phishing infrastructure or operational attack steps. The useful unit of analysis here is the identity lifecycle, not a recipe for interception.

Evidence

Microsoft documented campaigns in which a proxy relayed the sign-in flow, captured credentials and a session cookie, and then reused that session for follow-on access. The observed activity included mailbox access and financial fraud. The important detail is that possession of a valid session can move the attacker past the point where the original factor is checked.

CISA distinguishes ordinary MFA from phishing-resistant MFA and identifies FIDO/WebAuthn as the widely available phishing-resistant option. FIDO credentials are scoped to a relying-party origin. A lookalike origin cannot ask the authenticator to produce a valid assertion for the real service.

The FIDO deployment guidance adds an uncomfortable but necessary detail: a strong login method is not the entire account. Recovery and fallback paths are also forms of authentication. Leaving a weaker recovery method in place can preserve the path an attacker needs.

Finding

The phrase MFA bypass is too broad for useful engineering. I now ask which artefact the attacker acquired: a password, an approval, a session, a recovery path, or a newly registered factor. Each leaves different telemetry and demands a different response.

Phishing-resistant authentication reduces a major class of relay attacks because the credential is bound to the legitimate origin. It does not make session handling, endpoint security, token lifetime, or recovery controls irrelevant. Those controls become more visible once the password is no longer asked to carry the whole defence.

Limitations

This article synthesises published guidance and one documented campaign family. Identity platforms implement sessions and conditional access differently, so responders still need vendor-specific telemetry and local policy context.

Passkeys also involve deployment and recovery trade-offs that cannot be settled by a general article. The conclusion is narrower: name the stolen capability precisely, prefer origin-bound authentication, and audit every fallback that can recreate access.