Multifactor authentication (MFA) is a cornerstone of modern cyber defence, but how MFA gets hacked is a topic often misunderstood by professionals. Despite its growing usage, attackers continue to bypass MFA through various sophisticated techniques, putting organisations at risk.
Common Methods Attackers Use to Bypass MFA
Understanding how MFA gets hacked requires examining the main threat modalities and bypass techniques. Attackers regularly exploit well-known weaknesses in both the implementation and operation of MFA systems, with several high-profile incidents underscoring the risks.
Phishing and Social Engineering Attacks
Phishing remains one of the most effective ways to hack MFA. Attackers build convincing fake login pages to trick users into entering both their credentials and one-time codes. With AI-powered phishing kits, these attacks have grown more convincing, as seen in recent incidents where cloud keys and SSH access data were compromised via tailored phishing campaigns. Attackers can exploit real-time proxying tools to intercept codes and immediately use them to gain access.
MFA Fatigue and Prompt Bombing
MFA fatigue attacks, sometimes called prompt bombing, involve flooding a user with authentication requests. Eventually, the overwhelmed user may approve a request by accident, especially if the prompts are delivered via push notifications. Recent breaches at major identity providers, including Okta in 2023, highlighted how attackers abused support workflows and MFA fatigue to compromise sensitive systems. These attacks exploit user behaviour and workflow weaknesses rather than technical flaws.
Man-in-the-Middle (MitM) and Session Hijacking
Advanced attackers can deploy man-in-the-middle proxies to intercept MFA tokens and session cookies. By presenting a user with what appears to be a legitimate login page, the attacker captures all required credentials and session information. This enables them to bypass MFA and maintain persistent access. MitM attacks are particularly effective against SMS and push-based MFA, which lack resilience to real-time interception.
SIM Swapping and Voice-Based Attacks
SMS and voice call MFA are vulnerable to SIM swapping, where an attacker tricks a mobile provider into transferring a victim’s number to a new SIM card. Once complete, the attacker intercepts MFA codes sent via SMS or call. This technique is especially dangerous for organisations still relying on these legacy MFA methods.
- Phishing: Fake login pages, real-time interception
- MFA fatigue: Excessive push requests, social engineering
- MitM: Session hijacking, credential harvesting
- SIM swapping: SMS interception, phone-based attacks
Recent Incidents and the State of MFA Adoption
Despite guidance from major vendors like Google and Microsoft, MFA implementation remains inconsistent. According to a JumpCloud 2025 survey, 87 percent of large enterprises regularly use MFA. However, only about a third of small and medium businesses (SMBs) report similar adoption rates. This gap leaves many organisations exposed to the latest MFA bypass attacks.
A Cisco Duo study found that while 87 percent of professionals recognise the importance of phishing-resistant MFA, less than 20 percent have deployed such solutions across their environments. This disconnect between awareness and action is exploited by attackers, who often target organisations with legacy or partial MFA coverage.
High-profile breaches, such as the Okta support system compromise in 2023, demonstrate the risks of incomplete MFA strategies. Attackers leveraged social engineering, MFA fatigue, and gaps in policy enforcement to steal source code, compromise supply chains, and abuse support channels. These incidents highlight the importance of closing coverage gaps and adopting phishing-resistant solutions.
MFA Bypass Methods Documented by Researchers
Security researchers and vendors have catalogued a variety of techniques used to bypass MFA. For example, Abnormal Security details emerging MFA bypass trends, while KnowBe4’s research outlines a dozen different exploit approaches, ranging from brute force to exploiting backup codes and fallback mechanisms. These findings emphasise that effective MFA is not just about technology but also strong policy, user training, and continuous monitoring.
Strategies to Prevent MFA Bypass
Reducing the risk of MFA compromise requires adopting both technical controls and operational best practices. The most effective measures are:
- Deploy phishing-resistant MFA: Implement FIDO2, passkeys, or security keys wherever possible. These methods bind authentication to the device and are immune to interception.
- Replace SMS and voice MFA: Move away from SMS and phone-based codes, as these are vulnerable to SIM swapping and call interception.
- Enable number matching on push notifications: Requiring users to match a code on their device reduces the risk of MFA fatigue attacks and prompt bombing.
- Increase MFA coverage: Ensure all users, applications, and privileged accounts are protected by strong MFA. Avoid partial implementations that leave gaps.
- Monitor for abnormal MFA activity: Set up alerts for unusual authentication behaviour, such as repeated push requests or login attempts from new locations.
Guidance and Resources
Several industry resources provide in-depth advice on strengthening MFA:
- FIDO Alliance guidance on phishing-resistant authentication
- Abnormal Security’s MFA bypass techniques glossary
- KnowBe4’s MFA attack methods slide deck
- Cisco Duo’s MFA evaluation guide
Why This Matters and What Organisations Should Do Now
With attackers routinely bypassing MFA using social engineering, technical exploits, and workflow abuse, organisations cannot afford to treat MFA as a set-and-forget solution. The consequences of MFA compromise include unauthorised access, data breaches, and downstream supply chain risks. To mitigate these threats, organisations must upgrade to phishing-resistant MFA, expand coverage, and monitor for signs of attack. Reviewing current MFA policies and closing coverage gaps is vital to stay ahead of evolving bypass techniques.
Originally reported by csoonline.com.






