Two-step authentication — MFA, as it appears in settings — was for years the number one piece of security advice, and rightly so: a stolen password was no longer enough, and most mass attacks stopped there. The advice still stands today. Only the conclusion needs updating: MFA is no longer a guarantee, but an obstacle — one that attackers have learnt to bypass methodically.
It is not a reason to panic, and even less a reason to give up MFA. It is a reason to understand what the bypasses look like, because the defence differs from one to the next — and a few well-chosen settings make the difference between an MFA that ticks boxes on questionnaires and one that actually stops an attack.
This article is for companies that have switched on two-step authentication for email and the important applications and consider the matter closed. Below: the bypass methods, the signs that your MFA is only for show, and the concrete steps, in the order they are worth taking.
Why attackers moved to bypassing MFA
Simple: because MFA spread. As long as plain passwords were enough, nobody bothered with more; as more and more accounts gained extra protection, the bypass tools came down from the realm of sophisticated attacks into that of services for hire. Access to company infrastructure has itself become a commodity: ready-made access is sold on the dark web, and most of what is sold is access to SMEs — not to the corporations in the news. Small companies are the market's volume, precisely because their defence usually stops at “we switched on MFA”.
Five methods used to bypass two-step authentication
1. Real-time phishing
The classic fake site no longer collects just the password. The modern variant sits as a relay between the victim and the real site: you enter your password and MFA code on the fake page, it forwards them instantly, the session opens — for the attacker. Everything looks normal, because, from your point of view, you really did log in. The lure that brings you to the fake page is still an email or a message — and these have become noticeably more convincing since phishing became AI-generated.
2. MFA fatigue
The attacker has the password (bought or stolen) and triggers the login again and again: the victim's phone receives approval notifications in series, in the evening, at the weekend, in a meeting. Many accounts have fallen to a single tired finger that pressed “Approve” to stop the ringing. The telephone variant is even more effective: “I'm from IT, a notification will appear, please approve it”.
3. Session theft
After login, the browser keeps an “entry ticket” — the session — so it does not ask for your code at every click. Infostealer programs, installed through an infected download, steal exactly these tickets: with your session copied, the attacker is already inside, and MFA is never asked at all.
4. Duplicating your phone number
SMS codes depend on the SIM card. An attacker who convinces the operator to issue a duplicate of your number receives the codes instead of you. It is a targeted attack, not a mass one — but exactly the accounts worth targeting (administrators, management, banking) are the ones for which SMS is no longer a good idea.
5. Social engineering at the support desk
When the technology holds, the procedure gets attacked: one convincing phone call to the support desk — “I've lost my phone, please reset my MFA” — and the obstacle disappears entirely. The target is not the user, but the account recovery process.
The signs that your MFA is only for show
- The second factor is SMS, everywhere, including on administrator accounts.
- Approval is a simple tap on “Yes”, with no context check at all.
- Sessions practically never expire — you logged in in January and you are still inside today.
- There are “convenience exceptions”: management, the service account, the old application that “doesn't work with MFA” and stayed on a plain password.
- Nobody ever looks over the log of failed or odd sign-ins.
What works: phishing-resistant MFA
The order below is also the order of effectiveness:
- Hardware keys or passkeys for the critical accounts. The methods in the FIDO family tie authentication to the real site: on the fake page they simply do not work, and the relay from method 1 comes away empty-handed. Administrators, finance and management are the first candidates.
- Number matching instead of blind approval. If the app asks you to type the digits shown on the login screen, there is no more “I pressed Approve by reflex” — MFA fatigue loses its object.
- Conditional access rules. Sign-ins from unusual places, devices or situations get extra requirements or are blocked. The cloud services you probably already use include this; it needs configuring, not buying — and if the company is in the middle of moving to such services, the frequently asked questions about cloud and migration put the security side in context too.
- Shorter sessions and revocation on suspicion. If a stolen “entry ticket” expires quickly and can be cancelled centrally, session theft becomes a narrow window, not a permanent door.
- Removing SMS from the important accounts and replacing it with an app or a hardware key.
- An MFA reset procedure with real identity verification — so that method 5 does not bypass everything you built in points 1–4.
The plan for an SME, without drama
It does not all have to be done at once. Split the accounts in two: the critical ones (IT administration, management's email, finance and banking) get the full treatment — hardware keys or passkeys, short sessions, zero SMS. The rest get an authenticator app with number matching and conditional access rules. Then two small things with a big effect: tell your people, in a ten-minute conversation, what MFA fatigue is — “if you receive an approval request you did not ask for, it is an attack, report it immediately” — and establish who has the right to reset someone's MFA and on the basis of which checks.
If you do not know what exactly your platform allows or where to start without locking out half the company on Monday morning, an applied IT consulting discussion clarifies in a few hours the right configuration for your specific environment.
The next step: open today the list of accounts with administrator rights and check, for each one, two things — which second factor it uses and when its sessions expire. That is where, most of the time, the fate of the entire infrastructure is decided. Neoxis, an IT services company founded in 2015 in Pitești, ISO 27001 certified, works with SMEs across Romania.