For years we’ve told people to enable Multi-Factor Authentication (MFA), and that’s still excellent advice. If someone steals your password, MFA is one of the best defenses you can have.
But attackers have adapted.
Instead of trying to crack Microsoft’s authentication systems, they’re targeting something much easier: people.
Sometimes They Steal Your Session
One of the more sophisticated attacks today is known as an Adversary-in-the-Middle (AiTM) attack.
You click a link, and in order to view it, you’re presented with what appears to be a legitimate Microsoft 365 login page.
You enter your username and password (or your browser fills them in automatically) and approve the MFA request. Everything looks completely normal.
Behind the scenes, however, the attacker captures your authenticated session and uses it to access your account. They never needed your password, and they didn’t break your MFA. They simply stole your authenticated session and can now access your account from their own device.
Sometimes They Wear You Down
The technical term is MFA bombing.
Your phone starts buzzing with text messages or repeated authenticator prompts. Sometimes these attacks succeed because you’re distracted and instinctively approve the request—or even tap it by accident. Other times, people simply think, “I’ll approve it so these notifications stop.”
That’s all the attacker needed.
Once approved, they can quickly make changes to your account, register new authentication methods, or take other actions that make it much harder to remove them later.
And Sometimes…
They simply ask.
A significant number of successful attacks don’t involve sophisticated malware or advanced hacking techniques.
The attacker calls or sends a text claiming to be Microsoft, your bank, PayPal, your credit card company, Intuit, or even your technology support provider.
They’ll say something like:
“I’m sending you a verification code. Can you read me the six digits?”
Or…
“Can you approve the notification so I can verify your identity?”
And people do.
Not because they’re careless, but because they’re busy—and because the attacker is highly trained to sound legitimate.
This is classic social engineering, and it remains one of the most effective ways to compromise accounts. In fact, cybercriminals continue to get better at it.
Attackers understand something we’ve known for years in cybersecurity:
If you can manipulate the person, you often don’t have to defeat the technology.
So, Is MFA Important?
Absolutely.
Just think of it as one layer of your security strategy—not a silver bullet.
The organizations that do the best job protecting identities don’t rely on a single security feature. They build layers:
- Multi-Factor Authentication
- Conditional Access policies
- Phishing-resistant authentication
- Identity monitoring that looks for unusual sign-ins and suspicious behavior
- Ongoing user education focused on modern social engineering
No single layer is perfect, but together they create a much stronger defense.
Cybersecurity has never been just about technology. It’s about protecting identities, building smart processes, and helping people recognize the tricks that technology alone can’t stop.
One question to leave you with: If someone called one of your employees today claiming to be Microsoft and asked them to read off a six-digit verification code, would they know to say no?