When MFA Is No Longer Enough: How Modern Phishing Works
Multi-factor authentication is one of the most important security measures for Microsoft 365 today. However, modern phishing attacks demonstrate that MFA alone is no longer sufficient in every situation.
Traditional phishing works relatively simply: a fake website is designed to look like the Microsoft login page. If a user enters their email address and password, these credentials are captured by the attacker.
MFA makes this type of attack significantly more difficult. Even with a stolen password, the attacker still needs the second authentication factor.
Modern attacks therefore go one step further.
The attacker sits between the user and Microsoft
In a so-called Adversary-in-the-Middle attack, or AiTM, the phishing infrastructure effectively positions itself between the user and the legitimate Microsoft login service.
For example, a user opens a link from a convincing phishing email and arrives at a website that looks like Microsoft 365.
What the user does not see is that their interactions are being forwarded to Microsoft in real time.
A typical attack may look like this:
Microsoft describes AiTM as an attack technique in which authentication traffic is relayed in real time, potentially allowing attackers to capture credentials and session tokens.
But I have MFA enabled
This is precisely what makes these attacks so dangerous.
The user actually completes the MFA authentication. The authentication itself takes place with Microsoft. The attacker therefore does not necessarily need to technically break MFA.
Instead, the attacker tricks the user into successfully completing the authentication process.
The resulting authenticated session then becomes the valuable target. If an attacker obtains the relevant session cookie or token, they may be able to impersonate an already authenticated user and access Microsoft 365 services.
Microsoft has documented AiTM campaigns in which compromised sessions were subsequently used to access mailboxes and conduct Business Email Compromise attacks.
How can I recognise such a phishing page?
Unfortunately, this is becoming increasingly difficult.
The design, Microsoft logo, login forms and even the MFA process can appear extremely authentic.
One of the most important indicators is therefore the website address displayed in the browser.
A website can look exactly like Microsoft while actually being hosted on a completely different domain. Users should therefore carefully check the browser address whenever they receive an unexpected request to sign in.
Particular caution is required when an email or message unexpectedly asks you to log in again, access or approve a document, update your MFA configuration or perform an allegedly urgent security action.
Attackers increasingly use multiple professionally designed pages and redirects before presenting the actual phishing login page. This can make the attack significantly more difficult to recognise.
Does this mean MFA is useless?
No. Quite the opposite.
MFA remains an essential security measure and prevents many traditional attacks against user accounts.
However, it is becoming increasingly important to consider which type of MFA is being used.
SMS codes, one-time passwords and simple push approvals can be vulnerable to certain phishing techniques because the authentication process can potentially be relayed or unintentionally approved by the user.
Microsoft therefore increasingly recommends phishing-resistant authentication methods.
These include, for example:
- Passkeys
- FIDO2 security keys
- Windows Hello for Business
- Certificate-based authentication
Passkeys and FIDO2 work differently from traditional passwords and one-time codes. Authentication is cryptographically bound to the legitimate website or service. A phishing website therefore cannot simply relay the authentication process to Microsoft in the same way.
Technology alone is not enough
Businesses should not rely on a single security measure.
In addition to strong authentication, an effective security strategy can include Conditional Access, managed and compliant devices, monitoring of suspicious sign-ins, protection against malicious websites and emails, and regular security awareness training for employees.
Microsoft 365 access can also be restricted based on device identity and compliance. This makes it considerably more difficult for an attacker to use a stolen session from an unknown or unmanaged device.
What does this mean for businesses?
Cybercriminals continuously adapt their methods. Security measures that provided strong protection several years ago should therefore be regularly reviewed and improved.
For Microsoft 365 environments, the message today is clear:
Enabling MFA is the beginning. Phishing-resistant MFA, Conditional Access, secure endpoints and continuous monitoring are the next step.
Leftclick supports businesses in securing their Microsoft 365 environments, from multi-factor authentication and Conditional Access to Managed Workplace, device management and continuous security monitoring.
If you would like to know how well your Microsoft 365 environment is protected against modern phishing attacks, feel free to contact us.