All Guides
MFA Bypass Guide

MFA bypass: why your MFA might not be enough anymore

MFA is still essential. It blocks the vast majority of automated credential attacks. But in 2026, attackers regularly defeat SMS, push and code-based MFA in real time. This guide explains how, why phishing-resistant MFA matters, and how to move there without breaking your business.

Last updated April 202612 min read

Why MFA fails in 2026

For years, the message was simple: turn on MFA and you stop 99% of identity attacks. That was true when attackers were running automated password-spray tools. It is no longer fully true. The Huntress 2026 Cyber Threat Report and the ACSC 2024 to 2025 Annual Cyber Threat Report both highlight a sharp rise in attacks that succeed despite MFA being enabled.

The reason is that not all MFA is created equal. SMS codes, voice calls, push notifications and even Time-based One-Time Passwords (TOTP) can be defeated by techniques attackers use every day in 2026.

18.9%

Of 2025 identity incidents involved AiTM. Source: Huntress 2026

37.2%

Suspicious logins, often despite MFA. Source: Huntress 2026

Hours

Time from credential capture to financial loss in many BEC cases

How attackers bypass MFA, in plain English

Adversary-in-the-Middle (AiTM)

A phishing kit (Evilginx, Tycoon 2FA, Mamba 2FA) sits between the user and the real Microsoft login page. The user enters their password and code on the fake page. The kit forwards the request to Microsoft, captures the session token, and reuses it. MFA is technically completed, but the attacker now has a valid session.

Push fatigue (MFA bombing)

The attacker has the password and triggers push notifications repeatedly until the user accidentally approves one, often late at night.

SIM swap

The attacker convinces the mobile carrier to port the victim's number to a SIM they control, then receives the SMS code. Australian carriers have improved controls but the risk is not zero.

Token theft from infostealer malware

Malware on a personal or work device steals browser cookies and session tokens, which the attacker replays from their own machine. No MFA prompt is required.

OAuth consent phishing

A user clicks a link and grants a malicious app permission to read mail and files. No password or MFA is touched at all. The app uses its own granted access.

Help desk social engineering

The attacker calls the IT help desk pretending to be the user and convinces an agent to reset MFA or add a new device. This is how several large 2024 to 2025 breaches started.

Phishing-resistant MFA: what actually stops AiTM

"Phishing-resistant" is a specific term. It means the MFA method is bound to the legitimate website or application, so a fake site cannot relay the authentication. The ACSC and Microsoft both now recommend phishing-resistant MFA for all privileged accounts.

Passkeys are the consumer-facing form of phishing-resistant MFA. If you need to explain them to staff first, share our plain-English passkey guide.

FIDO2 security keys

Hardware keys (YubiKey, Feitian, Token2) that use public key cryptography bound to the legitimate domain. AiTM kits cannot relay them. The gold standard for admins.

Passkeys

Phishing-resistant credentials stored on the device (phone, laptop). Synced through Apple, Google or Microsoft accounts. Now supported broadly across Microsoft 365.

Windows Hello for Business

Biometric or PIN auth backed by a TPM-protected key, bound to the device. Strong option for managed Windows endpoints.

Certificate-based authentication

Uses a certificate provisioned to the device. Strong, but more operational overhead. Suits regulated environments.

Layer this with Conditional Access policies that require token protection, block legacy authentication, restrict logins to compliant devices, and limit access by location. The combination of phishing-resistant MFA plus strong Conditional Access is what closes most of the AiTM gap.

A realistic rollout plan

Audit current MFA methods in your tenant (Microsoft Entra sign-in logs)
Identify privileged accounts: global admins, finance, exec assistants, payroll
Issue FIDO2 security keys to all privileged accounts as the first wave
Enable Conditional Access policies requiring phishing-resistant MFA for admin roles
Roll out passkeys or Windows Hello for Business to general staff
Disable SMS as an authentication method for high-value accounts
Implement number matching for any remaining push-based MFA
Train help desk on identity verification before any MFA reset
Enable Identity Threat Detection and Response to catch AiTM patterns
Run a tabletop test, including a simulated MFA reset social engineering call

Australian regulatory context

ACSC Essential Eight

Multi-Factor Authentication is one of the eight controls. Maturity Level 2 and 3 specifically reference phishing-resistant MFA for privileged users and remote access. Reference: cyber.gov.au essential-eight-maturity-model.

APRA CPS 234

APRA-regulated entities are expected to maintain controls commensurate with the threat. Continuing to rely solely on SMS or push for privileged access is increasingly difficult to justify.

Cyber insurance

Most Australian cyber insurers now ask specifically about MFA on email, remote access and admin accounts at renewal. Several have moved phishing-resistant MFA into preferred risk criteria for premium discounts.

Want to know which of your MFA methods are still risky?

Real Bytes runs an identity hardening assessment that audits your authentication methods, Conditional Access posture and admin protections against current attacker techniques.