You Have MFA, So How Did the Hacker Still Get In?

A minimalist illustration of a digital shield being bypassed by a shadow figure

For years, the advice from IT professionals has been consistent and clear: “Enable Multi-Factor Authentication (MFA).” It was hailed as the silver bullet of cybersecurity, the one tool that could stop 99% of bulk identity attacks.

In 2026, however, the landscape has shifted. If you’re a business owner in Portland, ME, or anywhere across New England, you might have recently heard a story, or perhaps experienced one, where a hacker gained access to a Microsoft 365 account despite MFA being active.

It’s an eye-opening realization: MFA is no longer a “set it and forget it” solution. Recent sophisticated phishing campaigns documented by Microsoft and CISA have proven that attackers have evolved. They aren’t just trying to guess your password anymore; they are stealing the very keys that MFA provides.

The Myth of the MFA Silver Bullet

The problem is that most business owners view MFA as a locked door. If the door is locked, the hacker can’t get in, right?

In reality, modern hackers aren’t trying to pick the lock. They are waiting for you to unlock the door yourself and then slipping in behind you. This is known as session hijacking, and it’s the most common way hackers are bypassing MFA today. They don’t need your password, and they don’t need to crack your MFA code. They just need your “authenticated session.”

How It Works: The “Attacker-in-the-Middle” (AiTM)

One of the most effective techniques used in 2026 is the Adversary-in-the-Middle (AiTM) attack. Attackers use frameworks like Evilginx or Tycoon2FA to act as a transparent proxy between you and the real login page.

Diagram showing a user, an attacker as a middle bridge, and a server

Here is how a typical AiTM attack unfolds:

  1. The Lure: You receive a convincing email (perhaps about a “Code of Conduct” update or a “Shared Document”).
  2. The Proxy: You click the link and land on a page that looks identical to the Microsoft 365 login screen. In fact, it is the real login screen, but it’s being fed to you through the attacker’s server.
  3. The Interception: You enter your username and password. The attacker’s server passes these to Microsoft in real-time.
  4. The MFA Completion: Microsoft sends you an MFA prompt (a push notification or SMS code). You complete it, thinking you are logging in securely.
  5. The Theft: Once Microsoft confirms your identity, it issues a session cookie to your browser. This cookie is what tells the website, “This person is already logged in; don’t ask for MFA again for another 30 days.” The attacker’s proxy captures this cookie before it even reaches you.

With that cookie, the attacker can now impersonate you on their own device from anywhere in the world. They have your “authenticated session,” and they never had to bypass the MFA, they just stole the result of it.

The Device Code Trick: MFA “Bypass by Design”

Another sophisticated method involves abusing the OAuth 2.0 device code flow. You’ve likely used this when signing into a smart TV or a printer: you go to a URL, enter a short code, and your device is magically signed in.

Attackers initiate this flow on their own server and then trick you into entering the code on the legitimate Microsoft device-login portal. Because you are using the real portal, you feel safe completing the MFA. However, once you click “Approve,” the authentication token is issued to the attacker’s device, not yours. It’s a “bypass by design” because the attacker is essentially using your legitimate authentication to fuel their session.

Why SMS and Push Notifications Aren’t Enough

If your business is still relying on SMS codes or standard “Approve/Deny” push notifications, you are vulnerable to these 2026-style attacks. These methods are “phishable” because they don’t verify where the authentication request is coming from.

For New England SMBs, the risk is compounded. Many local businesses operate across multiple locations or have remote employees who are frequent targets for these types of “session theft” campaigns.

What You Should Do Instead: Moving to Phishing-Resistant MFA

The Cybersecurity and Infrastructure Security Agency (CISA) now recommends that businesses move toward phishing-resistant MFA. This is the only way to truly neutralize AiTM and session hijacking attacks.

A modern hardware security key glowing with blue light
  • FIDO2 Hardware Keys & Passkeys: These devices (like YubiKeys) use cryptography that is bound to the specific website URL. If you are on a proxy site like microsoft-security-update.com instead of microsoft.com, the key simply won’t work. It cannot be phished.
  • Conditional Access Policies: At Peak Technology Consulting, we help businesses implement Microsoft Entra ID (formerly Azure AD) policies that block risky flows like “device code” for most users and restrict logins to managed, known devices.
  • Continuous Access Evaluation (CAE): This technology allows Microsoft 365 to revoke a session cookie immediately if something suspicious happens: like a user’s location suddenly jumping from Portland to an overseas IP address.
  • Token Protection: This binds the session token to the specific device it was issued to, making it useless even if a hacker manages to steal the cookie.

Monitoring: The Final Line of Defense

No security measure is 100% foolproof. That’s why proactive monitoring is essential. Our team at Peak Tech monitors sign-in logs for anomalous patterns, such as “impossible travel” or suspicious token reuse.

A magnifying glass highlighting a threat in a digital log

A Note on AI and Security

As businesses in New England look to leverage AI tools like Microsoft Copilot to drive efficiency, authentication becomes even more critical. AI has access to your business data, which means a hijacked session could give an attacker the ability to query your entire company history through an AI interface. When implementing AI workflows, it is vital to ensure that permissions are tightly managed and that access is secured with the phishing-resistant controls mentioned above.

How Peak Technology Consulting Can Help

Navigating the complexities of modern identity security can be overwhelming for small to medium-sized businesses. You don’t need to be a cybersecurity expert; you just need a partner who is.

With over 20 years of experience providing managed IT services across New England, we specialize in securing Microsoft 365 environments against the latest threats. We help you move beyond “good enough” security to a posture that truly protects your business continuity.

Ready to secure your identity and explore what AI can do for your business?

Let’s have a conversation about auditing your MFA posture and identifying opportunities for AI workflow automation using Microsoft Copilot and Copilot Studio.

Schedule a Consultation with Peak Technology Consulting Today

Leave a Comment

Your email address will not be published. Required fields are marked *