Blog - IT & Cybersecurity News | TMGC

MFA Bypass Attacks: The New Way Hackers Get Past Your Login Screen

Written by Tony DiDonato | Aug 21, 2026, 9:16:24 PM

We started telling clients to turn on multi-factor authentication years ago, back when most business owners had never heard the term. It felt like the right call, and it still is. But over the last couple of years, we've watched something change.

We've had clients call us convinced they were covered because MFA was turned on, only to find out an attacker had been sitting inside their Microsoft 365 account for days. Like most of their advancements, attackers figured out how to work around it instead of through it.

That's what an MFA bypass attack is: a set of tactics hackers use to get past your login screen without ever guessing your password or beating MFA head-on. If you're a business owner who checked the MFA box a while back and moved on, this is worth ten minutes. We'll walk through how these attacks work, why "we have MFA" isn't the same as "we're protected," and what closes the gap for good.

 

Key Takeaways

  • MFA blocks the vast majority of automated attacks, but it isn't unbeatable. Hackers now target the process around MFA instead of trying to guess their way through it.
  • The three most common bypass tactics are prompt bombing (wearing you down with fake login requests), adversary-in-the-middle phishing (stealing your session after you approve a legitimate-looking login), and SIM swapping (hijacking your phone number to intercept text codes).
  • Basic MFA (text codes, push approvals) is far more vulnerable than phishing-resistant MFA (passkeys, hardware security keys).

 

Table of Contents

  1. What Is an MFA Bypass Attack?
  2. How Hackers Get Past MFA
  3. Why "We Have MFA" Isn't the Same as "We're Protected"
  4. How to Prevent MFA Bypass Attacks
  5. Frequently Asked Questions

 

What Is an MFA Bypass Attack?

An MFA bypass attack is any method hackers use to get into an account protected by multi-factor authentication without legitimately passing that second check. Instead of trying to defeat the encryption behind MFA, attackers go after the moment where a human has to make a decision, like approving a push notification or reading back a code.

MFA checks your identity once, at the moment you log in. It doesn't keep checking after that. Once an attacker has a valid session, whether they tricked you into approving it or stole the token some other way, MFA has already done its job and stepped aside. That single-moment design is exactly what these attacks are built to exploit, and it's the same weak spot we covered in our guide to credential theft, where identity itself has become the real perimeter businesses need to defend.

 

How Hackers Get Past MFA

Attackers have a small toolkit of tactics, and they'll try whichever one fits the target. Three show up in real incidents more than any others.

Prompt Bombing (Push Fatigue)

This one's simple and it works because people get tired. An attacker who already has your password sends a wave of MFA approval requests to your phone, sometimes dozens in a row, often late at night or during a busy stretch of the workday. Eventually, someone taps approve just to make the notifications stop, or they mistake it for a login they actually made.

A contractor at Uber approved a login after being hit with repeated push notifications, and Cisco had an employee give in after a barrage of voice phishing calls and push notifications. Both led to real breaches. The attack doesn't need to be clever, it just needs to outlast your patience.

 

Adversary-in-the-Middle (AiTM) Phishing

This is the tactic we're most concerned about right now, and it's the same technique we dug into in our post on session hijacking. An attacker sends a phishing link that routes you through a fake login page sitting between you and the real Microsoft or Google login. You enter your password, approve the MFA prompt, and continue as normal.

Behind the scenes, the attacker's proxy server is capturing your login and the authentication cookie that comes after it. That cookie is what lets them into your account without ever needing your password or a second MFA approval again. Kits built for this exact purpose, like Evilproxy and Tycoon 2FA, are sold and rented on the dark web, which means this isn't limited to elite hacking crews anymore. Anyone willing to pay can run this playbook.

 

SIM Swapping

If your MFA still relies on text messages, this one should get your attention. An attacker gathers enough personal details about you, often from social media or old data breaches, then calls your cell carrier pretending to be you. They convince a support rep to move your phone number onto a SIM card the attacker controls. From that point on, every text code meant for you goes straight to them instead.

The FBI logged nearly $50 million in losses tied to SIM swapping and port-jacking scams in a single year, and the tactic has been used against everyone from crypto holders to Fortune 500 executives.

 

Why "We Have MFA" Isn't the Same as "We're Protected"

Here's where we push back on how most of the industry talks about MFA. A lot of MSPs treat MFA like a box to check, something you turn on once during onboarding and never look at again. That mindset is part of the problem.

Not all MFA is built the same. Text codes and app push notifications, the kind most businesses default to, are the exact methods every tactic above is designed to beat. Phishing-resistant MFA, like passkeys and hardware security keys, works on a different principle entirely. Instead of a code that can be intercepted or a prompt that can be approved by mistake, these methods use a cryptographic key tied to your specific device and the specific website you're logging into. An attacker's fake login page simply doesn't have the key, no matter how convincing it looks.

Microsoft's own data backs this up: phishing-resistant methods sign users in three times more successfully than passwords paired with traditional MFA, and they do it in a fraction of the time. This isn't a tradeoff between security and convenience. Done right, it's better at both.

 

How to Prevent MFA Bypass Attacks

Preventing these attacks starts with adding a few layers most businesses skip.

  1. Move to phishing-resistant MFA where you can: Passkeys and FIDO2 security keys should be the standard for anyone with access to email, financial systems, or client data, not just IT staff.
  2. Turn on number matching: If you're still using push-based MFA for some accounts, number matching forces the user to type a code shown on their screen instead of just tapping approve. It kills prompt bombing outright, and CISA has been recommending it as a stopgap for exactly that reason.
  3. Set conditional access rules: A login attempt from a new country at 3am should trigger extra scrutiny. Conditional access policies do that automatically, without slowing your team down during a normal workday.
  4. Have someone watch for token theft and impossible travel: AiTM attacks succeed because nobody's looking for the aftermath. A monitored environment catches a stolen session token being used from an unfamiliar location, often before real damage is done.

This is the same thinking we bring to every managed cybersecurity engagement, and it's especially non-negotiable for businesses working under compliance requirements like CMMC, FINRA, or HIPAA, where "we had MFA" won't hold up to an auditor asking what kind.

MFA is still one of the best moves a business can make. Don't let this post talk you out of it. But if the version of MFA you have is text codes and push notifications set up years ago and never touched since, you're carrying more risk than you think. Attackers have had time to study the gaps, and they're using them.

If you're not sure what kind of MFA your business is running, or whether anyone's watching for the warning signs of a bypass attempt, it might make sense to consider our fractional IT service model. Reach out to TMGC and we'll tell you what's configured and what needs to change.

 

Frequently Asked Questions

Can MFA still be bypassed even if it's turned on?

Yes. MFA blocks most automated attacks, but tactics like prompt bombing, adversary-in-the-middle phishing, and SIM swapping are built specifically to get around it without ever breaking the encryption itself.

 

What is MFA prompt bombing?

Prompt bombing is when an attacker who already has your password sends repeated MFA approval requests, hoping you'll tap approve out of frustration or confusion. It's low-tech but has caused real breaches at major companies.

 

Is text-message based MFA safe?

It's better than no MFA, but it's the weakest form. SIM swapping lets attackers redirect your text codes to a phone they control, and SS7 network exploits can intercept SMS codes directly.

 

What's the difference between regular MFA and phishing-resistant MFA?

Regular MFA, like codes and push notifications, can be intercepted, approved by mistake, or stolen through a fake login page. Phishing-resistant MFA, like passkeys and hardware security keys, uses a cryptographic key tied to your device and the real website, so a fake page can't use it even if you're fooled into visiting one.

 

How do I know if my business has already been targeted by an MFA bypass attempt?

Warning signs include unexpected MFA push notifications you didn't trigger, login alerts from unfamiliar locations, or account activity happening while you're not actively working. If any of that sounds familiar, get it checked out right away.