Many organizations have turned on multifactor authentication and breathed a sigh of relief. That was the right move, and it blocks a large share of password-based attacks. But attackers have adapted. One technique, called adversary-in-the-middle phishing, can get around common forms of MFA without ever guessing a password or code.
Understanding how it works helps you decide which additional protections are worth the effort.
In an ordinary phishing attack, a fake page collects your password and the attacker uses it later. MFA defeats that, because the attacker lacks the code.
In an adversary-in-the-middle attack, the fake page acts as a relay. The victim clicks a link in an email or text and lands on a page that looks exactly like the real Microsoft 365 sign-in. Behind the scenes, the attacker's server passes everything the victim types to the real service and passes the real responses back. The victim enters a password and approves the MFA prompt or types a code, and the real service accepts it.
Here is the problem. After a successful sign-in, the service gives the browser a session token, a small credential that says this user is already verified. The attacker's relay captures that token. With it, the attacker can open the mailbox or files as that user, with no password or MFA prompt required, until the session expires or is revoked.
MFA protects the moment of sign-in against stolen passwords. It does not protect:
A session token that has already been issued and then copied.
Users who approve a prompt on a convincing fake page.
Sign-ins that rely on codes or push approvals that can be relayed.
This is why you may hear about an account being taken over even though MFA was on. It does not mean MFA is worthless. It means MFA is one layer.
Once inside a mailbox, attackers commonly look for invoices and payment conversations, create hidden inbox rules to conceal their activity, send further phishing from the trusted account, or register their own MFA method to keep access. In healthcare, a hijacked mailbox may expose protected health information, which can trigger breach analysis obligations under HIPAA.
Methods based on FIDO2 security keys or passkeys tie authentication to the real website's address. A fake page on a different domain cannot complete the sign-in, which defeats the relay trick. Consider these first for administrators, finance staff and anyone with broad access, then expand as practical.
Where your licensing allows, set rules about when sign-ins are accepted. Requiring a managed, compliant device, or limiting sign-ins from unexpected countries, makes a stolen token much harder to use from the attacker's computer.
Limit how long sessions last for sensitive roles, and know how to revoke all sessions for a user quickly if compromise is suspected. Resetting a password alone may not end an existing session.
Watch for signs of token theft: sign-ins from unusual locations right after a normal one, new inbox forwarding rules, newly registered MFA methods and impossible travel. Alerts on these events shorten the time an attacker has.
Teach staff to look at the address bar, to be suspicious of unexpected sign-in requests, and to report anything odd quickly. Make it easy to say, "I think I clicked something."
Confirm MFA is on for every account, with no exceptions.
Move administrators and high-risk roles to phishing-resistant methods.
Add device and location conditions to sign-in policies.
Review session lifetime settings and practice session revocation.
Turn on alerting for risky sign-ins and mailbox rule changes.
If you have MFA in place and wonder what comes next, this is the next step. UnityCare IT can review your sign-in policies, help roll out phishing-resistant methods where they matter most, and set up monitoring for the warning signs. We can also walk through an incident plan so your team knows what to do if a session is hijacked.
An outsourced IT department with proactive maintenance and one number to call.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172