Multi-factor authentication was supposed to end account takeover. For years, the advice was simple: turn on MFA and attackers move on to easier targets. That advice is now out of date.
Over the past year, attackers have shifted to techniques that don’t break MFA — they walk right around it. And the uncomfortable truth is that even a business with excellent security can still lose money to these attacks, because the weak link may not be your network at all. It may be a supplier’s.
Here’s what’s actually happening, and what to do about it.
How Attackers Get Past MFA Today
Modern account compromise rarely involves guessing a password. Three tactics dominate right now:
Adversary-in-the-Middle (AiTM) phishing. The victim clicks a link and lands on what looks exactly like the Microsoft sign-in page. It is the real login — the attacker is simply relaying it through their own server in the middle. The user types their password, completes MFA on their real phone, and everything works. But in that moment, the attacker captures the session token Microsoft issues after login — the digital “pass” that proves you’re already authenticated. With that token, they don’t need your password or your MFA again. Microsoft observed a single AiTM campaign hit 35,000 users in three days, and one incident-response firm found MFA failed to stop the attack in 84% of the cases it investigated.
Device-code phishing. This one abuses a legitimate Microsoft feature. The attacker sends what looks like a routine prompt (“enter this code to finish signing in”). The victim enters the code on the genuine Microsoft page and approves it with their own MFA. Because every step happens on Microsoft’s real infrastructure, nothing looks wrong — but the approval hands the attacker a valid access token. In May 2026 the FBI issued a public warning about Kali365, a subscription “phishing-as-a-service” kit built specifically to run this attack at scale using AI-generated lures.
Token theft and quiet persistence. Both methods produce the same result: the attacker gets access and refresh tokens rather than a password. That means they can stay in the mailbox for as long as the token is valid — often without tripping a single alert — reading email, learning your billing cycles, and studying who pays whom.
The common thread: MFA verifies you once, at the front door. Once an attacker holds a valid session, the door stays open behind them.
What We Can Do About It
The good news: this is defensible. Go West IT works with clients on projects to harden Microsoft 365 against exactly these techniques — phishing-resistant sign-in methods, Conditional Access policies that restrict risky flows like device-code authentication, and token protection and session controls that limit what a stolen session can do. And for clients on our Go Secured Advanced Cloud service, we provide proactive 24/7 monitoring that watches for the tell-tale sign of a stolen session: a familiar account suddenly signing in from an unfamiliar place or device. Together, these measures dramatically reduce the odds that your accounts become the entry point.
But here’s the part that matters most, and the reason we’re writing this.
The Gap You Can’t Close With Technology Alone
You can do everything right and still lose money — because the compromised mailbox doesn’t have to be yours.
Picture a supplier you pay every month. Their mailbox gets taken over using one of the tactics above. The attacker doesn’t send you a clumsy fake. They sit quietly inside the supplier’s real inbox, read the real invoice thread, and wait. When the genuine invoice goes out, they reply from the supplier’s actual address, inside the real conversation, with one change: new bank details, payment due Friday.
Every check your team knows to make passes. Right sender. Right thread. Right invoice number. Right amount. Nothing in your security stack fires, because nothing in your environment was breached. The money goes out — and weeks later the real supplier calls asking why they haven’t been paid.
No firewall, no MFA, and no monitoring on your side can catch this, because the fraud rides in on a legitimate relationship you’ve trusted for years. This isn’t an IT gap. It’s an operations gap — and the fix is operational.
- Verify every change of bank or wire details by phone, using a number from your own records — never a number or link from the email itself.
- Make that callback a written, mandatory step in your payment process, so skipping it is a policy breach, not a judgment call. Apply it to every vendor, including the ones you trust most.
- Ask your suppliers to do the same in reverse. Your mailbox is somebody else’s supplier thread.
Strong technology and strong procedure aren’t alternatives — you need both. We’ll help you lock down the technology. But the callback is the control that protects you when the breach happens somewhere you can’t see.
That’s the confident way to operate on today’s digital frontier: verify the change, then pay without hesitation.
Want to know where your Microsoft 365 environment — and your payment procedures — stand today? Our free Microsoft 365 Security Assessment gives you a clear, prioritized picture in plain language. Or if something already doesn’t sit right, let’s talk.