How Fake Invoice Scams Target BusinessesThe Invoice Looks Right. That’s the Problem.
Midyear Technology Checkup for Small BusinessesThe Midyear Technology Checkup Your Business Keeps Postponing
Learn how phishing attacks get past MFA and how phishing-resistant authentication, safer approvals, and stronger access controls protect accounts.

Your MFA Worked. The Hacker Got In Anyway.

Multifactor authentication is one of the most important security protections a business can use.

It adds another step beyond the password, such as an approval prompt, security code, fingerprint, passkey, or physical security key. That extra step makes it much harder for someone to access an account with a stolen password alone.

But MFA is not magic.

Modern phishing attacks are increasingly designed to trick employees into completing the authentication process for the attacker. The employee may enter the correct password, approve the legitimate prompt, and successfully complete MFA.

The security system works exactly as designed.

The problem is that the employee was authorizing the wrong session.

MFA Is Still Essential

This does not mean businesses should stop using multifactor authentication.

Passwords are frequently stolen, reused, guessed, or exposed through data breaches. MFA creates an important additional barrier that can stop many common account attacks.

CISA continues to recommend MFA for business accounts and encourages organizations to use phishing-resistant methods whenever possible.

The lesson is not that MFA has failed.

The lesson is that not every form of MFA provides the same level of protection.

How Can an Attacker Get Past MFA?

In many cases, the attacker does not technically break the authentication system.

Instead, they convince the employee to help complete it.

The request may look like:

  • A Microsoft 365 sign-in
  • A document-sharing invitation
  • A message from technical support
  • A device registration request
  • A prompt to reconnect an email account
  • A request to approve an unexpected login
  • A code that supposedly connects a printer, meeting room, or application

The employee sees a familiar sign-in page and follows the instructions.

Behind the scenes, the attacker is using those actions to gain access.

The Legitimate Microsoft Page Can Still Be Part of the Attack

One of the more confusing tactics involves device code authentication.

Device code flow is a legitimate sign-in process designed for devices that may not have a full keyboard or browser, such as smart televisions, printers, conference-room equipment, and shared displays.

A user receives a short code and enters it on a Microsoft authentication page using another device.

The page is real.

The sign-in process is real.

The MFA prompt may also be real.

The scam happens because the code was generated by the attacker.

When the employee enters that code and completes authentication, they may be granting the attacker access to company resources.

Microsoft documented a 2026 phishing campaign that used AI-assisted social engineering and legitimate device code authentication to compromise accounts. Microsoft also describes device code flow as a high-risk authentication method that can be abused in phishing attacks or used to access resources from unmanaged devices.

Why This Attack Is So Convincing

Employees are usually taught to look for fake sign-in pages.

They check the web address. They look for poor formatting. They avoid pages that do not appear legitimate.

That advice is still useful, but it is not enough for this type of attack.

The employee may be visiting Microsoft’s real website and using Microsoft’s real authentication system.

Nothing on the page necessarily looks fake.

The warning sign is not the appearance of the page.

It is the unexpected request that sent the employee there.

That is an important shift in security awareness. A legitimate website does not automatically make the instructions leading to it legitimate.

Another Threat: Adversary-in-the-Middle Phishing

Some attackers use a technique called adversary-in-the-middle phishing.

The employee is directed to a convincing sign-in page that relays information between the employee and the legitimate service in real time.

The employee enters a password and completes MFA. The attacker then captures the resulting session information or authentication token.

That token may allow the attacker to act as the user without repeatedly entering the password or completing MFA again.

In April 2026, Microsoft observed a multistage phishing campaign targeting more than 35,000 users across over 13,000 organizations. The campaign used adversary-in-the-middle techniques to compromise authentication tokens.

Microsoft’s security documentation also notes that stolen authorization codes or session tokens may allow an attacker to impersonate a user without needing the password or another MFA prompt.

The Guide to Better IT Service, Security, and Compliance

Get a clear, practical framework for evaluating IT providers. Learn the warning signs, security essentials, and key questions to ask before choosing a Managed IT partner.

MFA Fatigue Can Turn Security Into a Reflex

Another common tactic is repeated approval prompts.

An attacker obtains or guesses a password and attempts to sign in repeatedly. The employee receives multiple MFA notifications and eventually approves one to make the prompts stop.

Sometimes the attacker follows up with a phone call or message pretending to be technical support.

They may say:

  • We are testing your account
  • Approve the next prompt to restore access
  • Your email needs to be reconnected
  • We are updating company security
  • The previous request failed, so try again

MFA fatigue attacks work because people become frustrated, confused, or conditioned to approve prompts automatically.

An approval request should never be treated as a routine notification.

It is a security decision.

Five Rules That Make MFA Stronger

MFA works best when it is supported by clear employee habits and properly configured security controls.

1. Never approve an unexpected sign-in request

If an employee is not actively signing into an account, they should deny the prompt.

Repeated unexpected notifications may mean someone already has the password.

The employee should report the activity immediately rather than continuing to dismiss it.

2. Treat device codes like passwords

Employees should never enter a device code received through an unexpected email, chat message, text, or phone call.

A device code should only be used when the employee personally initiated the connection on a device they recognize.

If someone else sends the code, the request should be considered suspicious.

3. Verify support requests independently

Technical support should not unexpectedly ask an employee to approve a login, reveal a security code, or enter a device code.

When a request appears to come from IT, employees should contact the support team through a known phone number, ticketing system, or internal channel.

They should not use the contact information contained in the suspicious message.

4. Use phishing-resistant authentication where possible

Not all authentication methods are equally resistant to phishing.

SMS codes, one-time codes, and basic push notifications can still be intercepted or approved under false pretenses.

Phishing-resistant methods can include:

  • Passkeys
  • FIDO2 security keys
  • Windows Hello for Business
  • Certificate-based authentication
  • Other device-bound authentication methods

Microsoft recommends phishing-resistant options such as passkeys, FIDO2 security keys, and Windows Hello for Business. CISA also identifies FIDO and public key infrastructure as strong phishing-resistant approaches.

5. Restrict risky authentication methods

Businesses should review whether employees actually need device code authentication.

Microsoft provides Conditional Access controls that can restrict or block device code flow. Microsoft’s security defaults can also block the flow, although businesses should review compatibility before changing authentication policies.

These settings should be reviewed by someone who understands the company’s devices, applications, and access requirements.

Signs an Account May Have Been Compromised

MFA approval does not always produce an immediate, obvious problem.

Attackers may quietly review email, search for financial information, create inbox rules, or monitor conversations before taking further action.

Possible warning signs include:

  • Unexpected MFA prompts
  • Sign-ins from unfamiliar locations or devices
  • Emails marked as read without explanation
  • New forwarding or inbox rules
  • Messages sent from the account without the employee’s knowledge
  • Changes to recovery information
  • Newly registered authentication methods
  • Unusual file-sharing activity
  • Customers or vendors receiving strange messages
  • Missing emails or deleted notifications

These signs should be investigated quickly.

What to Do After an Accidental Approval

If an employee approves an unexpected prompt or enters a suspicious device code, changing the password is important, but it may not be enough.

A proper response may include:

  1. Reporting the incident immediately
  2. Changing the account password
  3. Revoking active sessions and authentication tokens
  4. Reviewing recent sign-in activity
  5. Removing unknown devices or authentication methods
  6. Checking mailbox forwarding and inbox rules
  7. Reviewing sent, deleted, and archived messages
  8. Checking file-sharing activity
  9. Confirming that recovery information was not changed
  10. Investigating whether other accounts or systems were accessed

The faster the business responds, the more likely it is to limit the damage.

A Quick MFA Security Check

Ask these questions about your company:

  • Does every employee use MFA?
  • Do employees know never to approve an unexpected prompt?
  • Would they recognize an unexpected device code request?
  • Can they report suspicious activity quickly?
  • Are privileged accounts protected more strongly?
  • Are legacy authentication methods blocked?
  • Has device code flow been reviewed?
  • Are phishing-resistant options available?
  • Are unusual sign-ins and authentication changes monitored?
  • Does the company know how to revoke active sessions after an incident?

MFA is most effective when it is part of a larger identity security strategy.

The Takeaway

Multifactor authentication remains essential.

But businesses should not assume that every successful MFA approval represents a legitimate employee sign-in.

Attackers are increasingly targeting the person and the authentication process instead of trying to break the technology directly.

The strongest approach combines:

  • MFA on every important account
  • Phishing-resistant authentication where possible
  • Clear employee verification habits
  • Restricted high-risk sign-in methods
  • Monitoring for unusual activity
  • A fast response process

Your MFA can work exactly as intended while an employee is still tricked into opening the door.

The goal is not only to require a second step.

It is to make sure that second step authorizes the right person, on the right device, for the right reason.

Strengthen the Security Behind Every Sign-In

Capital Network Solutions helps businesses evaluate identity security, multifactor authentication, Microsoft 365 protections, account monitoring, and incident response procedures.

A discovery call can help identify whether your current MFA setup is providing the protection you expect or whether risky authentication methods and approval habits leave room for attackers.

No scare tactics. Just a practical review of how your business protects access to its most important systems.

Let's Talk IT! (916) 866-9969

Capital Network Solutions, Inc. Logo

Need IT Guidance?

Talk with a CNS Advisor

Get practical help with technology, security and compliance questions from the CNS team.

  • Managed IT & Help Desk

  • Cybersecurity & Risk Reviews

  • Microsoft 365 & Cloud

  • Compliance Guidance

or call (916) 866-9969

  • 30+ years serving California businesses