Pular para o conteúdo principal
Close
Security

MFA No Longer Protects: AI Phishing Jumped 14x and AiTM Bypasses Everything

Gabriel Ferraresi· CEO | Tech86July 21, 20264 min
securityphishingaimfaaitmevilginxpasskeysfido2session-cookieaccount-takeover

MFA no longer protects. The phrase nobody wants to hear, but the data proves it. We have been tracking the evolution of phishing over the past few months and the signal is unequivocal: AI rewrote the rules of the attack, and traditional MFA is no longer sufficient control. The technical answer exists, it has a name — phishing-resistant MFA — and anyone still treating SMS or push as primary control is exposed.

The scale: AI phishing jumped 14x in one month

According to the Hoxhunt Phishing Trends Report 2026, phishing with AI-generation indicators jumped from 4% in November 2025 to 56% in December. A 14x increase in one month. The number dropped to 40% in January 2026, but remains well above the 4% baseline. That is 50 million data points, 4 million users, 125 countries.

Important context: 56% is the share of phishing emails that bypassed filters and were reported by users. The total universe is larger. The volume of sophisticated attacks grew during the holiday period. And it became more effective: according to the Microsoft Digital Defense Report 2025, AI-generated phishing has a 54% click rate vs 12% for manual phishing — 4.5x more effective. AI writes better than the human attacker. No spelling errors, perfect context, personalization at scale.

Traditional MFA doesn't hold: 59% of compromised accounts had MFA

According to Proofpoint data published in February 2026, 59% of successfully compromised corporate accounts had MFA enabled at the time of the attack. 99% of organizations suffered Account Takeover attempts. 67% suffered at least one successful ATO.

The data does not invalidate MFA. According to Microsoft itself, MFA still blocks more than 99% of identity-based attacks. The point is that sophisticated attacks bypass MFA instead of breaking it, and AI phishing dramatically increased the volume of those attacks. The traditional MFA pact — authenticate the user and consider the account protected — is over.

The mechanics: AiTM intercepts the session cookie after MFA

The attack bypasses MFA instead of breaking it. The mechanics are AiTM, Adversary-in-the-Middle: a real-time reverse proxy between the victim and the identity provider. Kits like Evilginx2, Muraena, and Tycoon 2FA host a login page identical to the original.

The user authenticates normally. Types the password, approves the push, completes MFA. Everything legitimate on their side. The session cookie — ESTSAUTH in Microsoft's case — is intercepted after authentication. The attacker enters the account without a new prompt, without new MFA, without alert. This is not MFA fatigue, where the attacker exhausts the user with push notifications. It is session interception: the attacker uses the stolen cookie as if they were the legitimate user.

The technical answer: phishing-resistant MFA with FIDO2 and passkeys

The technical answer is phishing-resistant MFA. FIDO2 and passkeys use channel binding: authentication is bound to the real origin, so the proxy cannot intercept the session. Even if the user accesses the attacker's cloned page, the authentication token is not valid for the fake origin — the browser refuses to hand it over.

Microsoft recommends it explicitly. NIST too. Anyone still treating SMS or push-based MFA as sufficient control is exposed. SMS is interceptable via SIM swap and SS7. Push is bypassable via AiTM. FIDO2 and passkeys are not bypassable by the AiTM kits in use today.

Defense in layers: awareness, resistant MFA, and session detection

Defense in layers is the model that works. Continuous awareness to reduce the click rate — AI phishing has a 54% click rate vs 12% for manual, according to Microsoft. Phishing-resistant MFA as primary control. And session anomaly detection to identify stolen cookies in use: impossible travel, atypical geography, token reuse.

This is where Tech86 has been working with corporate clients, integrating identity telemetry into the SOC. Isolated identity provider logs are not enough — the attack happens after authentication, and the SOC must correlate identity events with endpoint and network telemetry to catch AiTM in real time. Blocking AiTM kit infrastructure (Evilginx2, Muraena, Tycoon 2FA) with proactive domain takedown and URL filtering reduces the surface before the email reaches the inbox.

Session anomaly detection is the missing layer in most operations. A valid ESTSAUTH cookie used from an IP on another continent minutes after the legitimate login is the clearest signal of AiTM in progress. Without that layer, the attacker stays in the account for days or weeks — enough time for exfiltration, lateral movement, and persistence via backdoor.

Conclusion: the MFA pact is over

The MFA pact is over. AI rewrote the rules of phishing. Today the answer is phishing-resistant MFA. We help corporate enterprises migrate from SMS and push to FIDO2 and passkeys, integrate identity telemetry into the SOC, and reduce the click rate with realistic continuous training. There is no shortcut — there is identity architecture that survives AI-powered phishing and AiTM.

Need expert guidance?

Schedule a consultation with our specialists.

AI Phishing Defense and Phishing-Resistant MFA

Frequently Asked Questions

Because the attack bypasses MFA instead of breaking it. According to Proofpoint data published in February 2026, 59% of successfully compromised corporate accounts had MFA enabled at the time of the attack. AiTM uses a real-time reverse proxy between the victim and the identity provider — the user authenticates normally, but the session cookie is intercepted afterward. MFA still blocks more than 99% of identity-based attacks according to Microsoft; the problem is that sophisticated attacks bypass it and AI increased the volume of those attacks.

AiTM is a real-time reverse proxy attack between the victim and the identity provider. Kits like Evilginx2, Muraena, and Tycoon 2FA host a login page identical to the original. The user types the password, approves the push, completes MFA — everything legitimate on their side. The session cookie (ESTSAUTH in Microsoft's case) is intercepted after authentication. The attacker enters the account without a new prompt, without new MFA, without alert. It is not MFA fatigue — it is session interception.

According to the Hoxhunt Phishing Trends Report 2026, phishing with AI-generation indicators jumped from 4% in November 2025 to 56% in December — a 14x increase in one month. It dropped to 40% in January 2026, but remains above the 4% baseline. According to the Microsoft Digital Defense Report 2025, AI-generated phishing has a 54% click rate vs 12% for manual phishing — 4.5x more effective. AI writes without spelling errors, with perfect context and personalization at scale.

Phishing-resistant MFA is authentication that cannot be intercepted by a reverse proxy. FIDO2 and passkeys use channel binding: authentication is bound to the real origin, so the proxy cannot capture the session. According to Microsoft and NIST, both explicitly recommend FIDO2 and passkeys as primary control. Anyone still treating SMS or push-based MFA as sufficient control is exposed.

According to Proofpoint data published in February 2026, 59% of successfully compromised corporate accounts had MFA enabled at the time of the attack. In addition, 99% of organizations suffered Account Takeover attempts and 67% suffered at least one successful ATO. The data does not invalidate MFA — it shows that traditional MFA is bypassable by AiTM and that sophisticated attacks grew in volume.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.