Attack vector
MFA bypass
MFA bypass is defeating a second factor that is in place, rather than finding an account without one. Attackers flood users with push prompts until one is approved, relay one-time codes through a fake login page, swap a phone number to intercept texts or abuse a weak enrollment or recovery flow.
A second factor was defeated rather than absent — push fatigue, prompt bombing, or a bypassed enrollment flow.
How attackers use it
With a password already in hand, attackers trigger repeated push notifications late at night until a tired user taps approve. Others run a proxy login page that passes the real code through in real time, or talk a mobile carrier into moving the victim's number. Some skip the factor entirely by registering their own device through an enrollment or recovery step that asks for too little proof.
What breach letters say
1 distinct incident in California breach filings names this vector in the letter’s own words (January 1, 2023 – August 14, 2026).
“Based on our investigation and response to this event, however, it appears the threat actor was able to bypass the multi-factor authentication and other common security controls the company had in place that were designed to protect the company’s data.”
Bankers Life and Casualty Company · filed Jan 29, 2024 · letter
How to stop it
Use phishing-resistant MFA bound to the real site, such as FIDO2 keys or passkeys, and retire weaker fallback methods such as SMS codes and security questions. Where push is still used, require number matching, and protect MFA enrollment and recovery with the same strength as sign-in.
Terms under this vector
- AiTM phishing
AiTM phishing, or adversary-in-the-middle phishing, is a technique that places a proxy between the victim and the real login page.
- MFA fatigue
MFA fatigue is an attack that floods a user with multifactor push notifications until they approve one.
- SIM swapping
SIM swapping is tricking or bribing a mobile carrier into moving a victim's phone number onto a SIM card the attacker controls.
Threat actors tied to it
- ALPHV Blackcat
Profile with government sources
- APT29
Profile with government sources
- Scattered Spider
Profile with government sources
Last reviewed Oct 2, 2026