Why MFA fails in 2026
For years, the message was simple: turn on MFA and you stop 99% of identity attacks. That was true when attackers were running automated password-spray tools. It is no longer fully true. The Huntress 2026 Cyber Threat Report and the ACSC 2024 to 2025 Annual Cyber Threat Report both highlight a sharp rise in attacks that succeed despite MFA being enabled.
The reason is that not all MFA is created equal. SMS codes, voice calls, push notifications and even Time-based One-Time Passwords (TOTP) can be defeated by techniques attackers use every day in 2026.
18.9%
Of 2025 identity incidents involved AiTM. Source: Huntress 2026
37.2%
Suspicious logins, often despite MFA. Source: Huntress 2026
Hours
Time from credential capture to financial loss in many BEC cases
How attackers bypass MFA, in plain English
Adversary-in-the-Middle (AiTM)
A phishing kit (Evilginx, Tycoon 2FA, Mamba 2FA) sits between the user and the real Microsoft login page. The user enters their password and code on the fake page. The kit forwards the request to Microsoft, captures the session token, and reuses it. MFA is technically completed, but the attacker now has a valid session.
Push fatigue (MFA bombing)
The attacker has the password and triggers push notifications repeatedly until the user accidentally approves one, often late at night.
SIM swap
The attacker convinces the mobile carrier to port the victim's number to a SIM they control, then receives the SMS code. Australian carriers have improved controls but the risk is not zero.
Token theft from infostealer malware
Malware on a personal or work device steals browser cookies and session tokens, which the attacker replays from their own machine. No MFA prompt is required.
OAuth consent phishing
A user clicks a link and grants a malicious app permission to read mail and files. No password or MFA is touched at all. The app uses its own granted access.
Help desk social engineering
The attacker calls the IT help desk pretending to be the user and convinces an agent to reset MFA or add a new device. This is how several large 2024 to 2025 breaches started.
Phishing-resistant MFA: what actually stops AiTM
"Phishing-resistant" is a specific term. It means the MFA method is bound to the legitimate website or application, so a fake site cannot relay the authentication. The ACSC and Microsoft both now recommend phishing-resistant MFA for all privileged accounts.
Passkeys are the consumer-facing form of phishing-resistant MFA. If you need to explain them to staff first, share our plain-English passkey guide.
FIDO2 security keys
Hardware keys (YubiKey, Feitian, Token2) that use public key cryptography bound to the legitimate domain. AiTM kits cannot relay them. The gold standard for admins.
Passkeys
Phishing-resistant credentials stored on the device (phone, laptop). Synced through Apple, Google or Microsoft accounts. Now supported broadly across Microsoft 365.
Windows Hello for Business
Biometric or PIN auth backed by a TPM-protected key, bound to the device. Strong option for managed Windows endpoints.
Certificate-based authentication
Uses a certificate provisioned to the device. Strong, but more operational overhead. Suits regulated environments.
Layer this with Conditional Access policies that require token protection, block legacy authentication, restrict logins to compliant devices, and limit access by location. The combination of phishing-resistant MFA plus strong Conditional Access is what closes most of the AiTM gap.
A realistic rollout plan
Australian regulatory context
ACSC Essential Eight
Multi-Factor Authentication is one of the eight controls. Maturity Level 2 and 3 specifically reference phishing-resistant MFA for privileged users and remote access. Reference: cyber.gov.au essential-eight-maturity-model.
APRA CPS 234
APRA-regulated entities are expected to maintain controls commensurate with the threat. Continuing to rely solely on SMS or push for privileged access is increasingly difficult to justify.
Cyber insurance
Most Australian cyber insurers now ask specifically about MFA on email, remote access and admin accounts at renewal. Several have moved phishing-resistant MFA into preferred risk criteria for premium discounts.
Want to know which of your MFA methods are still risky?
Real Bytes runs an identity hardening assessment that audits your authentication methods, Conditional Access posture and admin protections against current attacker techniques.

Remote Support