Avatier

Attack vector

MFA bypass

MFA bypass is defeating a second factor that is in place, rather than finding an account without one. Attackers flood users with push prompts until one is approved, relay one-time codes through a fake login page, swap a phone number to intercept texts or abuse a weak enrollment or recovery flow.

A second factor was defeated rather than absent — push fatigue, prompt bombing, or a bypassed enrollment flow.

How attackers use it

With a password already in hand, attackers trigger repeated push notifications late at night until a tired user taps approve. Others run a proxy login page that passes the real code through in real time, or talk a mobile carrier into moving the victim's number. Some skip the factor entirely by registering their own device through an enrollment or recovery step that asks for too little proof.

What breach letters say

1 distinct incident in California breach filings names this vector in the letter’s own words (January 1, 2023 – August 14, 2026).

  • “Based on our investigation and response to this event, however, it appears the threat actor was able to bypass the multi-factor authentication and other common security controls the company had in place that were designed to protect the company’s data.”

    Bankers Life and Casualty Company · filed Jan 29, 2024 · letter

See the Identity Attack Ledger

How to stop it

Use phishing-resistant MFA bound to the real site, such as FIDO2 keys or passkeys, and retire weaker fallback methods such as SMS codes and security questions. Where push is still used, require number matching, and protect MFA enrollment and recovery with the same strength as sign-in.

Terms under this vector

  • AiTM phishing

    AiTM phishing, or adversary-in-the-middle phishing, is a technique that places a proxy between the victim and the real login page.

  • MFA fatigue

    MFA fatigue is an attack that floods a user with multifactor push notifications until they approve one.

  • SIM swapping

    SIM swapping is tricking or bribing a mobile carrier into moving a victim's phone number onto a SIM card the attacker controls.

Threat actors tied to it

Last reviewed Oct 2, 2026