Wednesday Wisdom: The MFA Illusion : Why Authentication Alone No Longer Protects Your Firm

Cybersecurity advisors collaborating with business leaders in a modern, naturally lit office

Multi-factor authentication remains an essential security control. It is not, however, a complete identity security strategy.

The outdated lens says that MFA protects the account because the user must prove who they are with more than a password. The modern reality is more precise. MFA protects the authentication event. It does not automatically protect the authenticated session that follows.

That distinction now carries direct consequences for firms managing client money, sensitive legal records, financial information, and confidential business strategy.

MFA can succeed while the attacker still wins

Adversary-in-the-middle, or AiTM, phishing attacks place a convincing login page between the employee and the legitimate Microsoft 365 authentication service.

The employee enters a username and password. The attacker relays those credentials to Microsoft in real time. The employee completes MFA. Microsoft approves the sign-in.

The authentication is genuine. The user has passed MFA.

The problem begins immediately afterward. The attacker captures the authenticated session cookie or token issued by Microsoft. That session can then be replayed from another device or location. The attacker does not need to ask for the password again or trigger a new MFA prompt.

This is not a cryptographic failure in MFA. It is a failure to protect the session created after MFA succeeds.

The fix is to move from an “MFA enabled” mindset to an identity protection model that also governs sessions, devices, tokens, applications, and sensitive actions.

Recent campaigns show why this change matters. ANY.RUN’s August 2026 reporting on Mirage2FA described activity affecting roughly 4,500 US and European organizations. The phishing-as-a-service kit relays Microsoft 365 sign-ins and captures authenticated session cookies after MFA is completed.

NovaCookies applies the same strategic weakness through a subscription model reportedly priced at approximately $320 per month. As reported by [The Hacker News in coverage of Island’s August 26 disclosure](https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html), the service abuses genuine-looking DocuSign notifications to lead employees into Microsoft 365 phishing flows.

DocuSign does not need to be compromised for the lure to be effective. The attacker only needs the message to feel familiar enough to earn a click.

Business advisor leading a focused cybersecurity strategy discussion with a professional team

The business risk is not only account takeover but trusted access

For an RIA, family office, wealth manager, law firm, medical group, or professional services firm, a compromised Microsoft 365 session can provide access far beyond an inbox.

Email often contains vendor relationships, payment instructions, client records, contracts, tax documents, legal correspondence, and internal approvals. Microsoft 365 identity may also provide access to SharePoint, OneDrive, Teams, and other connected applications.

The attacker does not need to behave like an intruder. They can behave like the employee.

An August 2026 case reported by [TrendAI](https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/how-aitm-phishing-bypassed-mfa-to-hijack-a-microsoft-365-mailbox-in-bec-scheme) illustrates the point. A finance employee received a targeted “PTO Request Denied” phishing email. The link led to a counterfeit Microsoft 365 sign-in page.

After the employee completed MFA, the attacker reused the stolen session. The activity remained in the cloud identity and email layer. No malware was required. No obvious endpoint compromise was present.

The attacker created mailbox rules that archived and marked vendor and collections messages as read. Those rules helped conceal fraudulent conversations while the attacker impersonated vendors and redirected payments. The campaign continued for approximately 30 days.

The fix is to treat email as an operational control surface, not simply a communication tool. Mailbox rules, forwarding settings, sign-in geography, token activity, and changes to payment-related conversations require executive-level oversight.

This is also why the [May 2026 AssetMark incident](https://www.mass.gov/doc/2026-962-assetmark-inc/download) is relevant to wealth management leaders. AssetMark disclosed that on May 15, 2026, an unauthorized party used compromised employee credentials to access and download files containing personal information, including names, addresses, Social Security numbers, financial account information, and government identification numbers. Reporting indicates roughly 570,000 individuals were affected, and AssetMark offered 24 months of credit monitoring. The point is not whether core systems or client assets were touched. It is that one employee identity became a pathway to sensitive client data.

A firm does not need to lose control of client assets for its leadership credibility, regulatory obligations, or growth reputation to be affected.

The first priority is phishing-resistant authentication for high-risk roles

Traditional MFA methods, including SMS codes, one-time passcodes, and push approvals, can be relayed in real time through AiTM phishing pages.

They remain better than password-only access. They are not equally resistant to modern session theft.

The fix is to require phishing-resistant MFA for administrators, executives, finance personnel, operations leaders, HR administrators, and anyone with access to client records or payment processes.

FIDO2 security keys and passkeys use cryptographic binding to associate the authentication with the legitimate website and device. A fake Microsoft 365 domain cannot easily obtain a valid authentication response from the user’s credential.

This should be prioritized by business risk rather than deployed as a vague technology upgrade. Begin with the accounts that can:

  • Approve payments or change vendor banking details.
  • Access client financial or personally identifiable information.
  • Modify identity, email, or security policies.
  • Create applications, permissions, or mailbox delegations.
  • Access multiple business systems through single sign-on.

A practical rollout does not need to wait for every employee. Leadership can establish a risk-based sequence and measure completion as part of the firm’s security governance.

Session theft requires identity incident response, not only a password reset

One of the most important leadership decisions is how the firm responds when session theft is suspected.

The outdated response is to reset the password and close the ticket. That may leave an active session or refresh token available to the attacker.

The fix is to treat suspected session theft as an identity incident.

The response should include:

  1. Revoke active sign-in sessions and refresh tokens.
  2. Force re-authentication after sessions are invalidated.
  3. Reset the password and verify that new authentication methods were not added.
  4. Review mailbox rules, forwarding settings, deleted items, and delegated access.
  5. Examine OAuth application consent and connected applications.
  6. Review SharePoint, OneDrive, Teams, and other single sign-on activity.
  7. Notify finance, legal, compliance, and executive stakeholders when business processes may have been affected.

Password changes still matter. They are one step in containment, not the complete response.

Cybersecurity professionals monitoring identity and infrastructure activity in a bright modern office

Conditional access and managed devices make stolen sessions less useful

A valid session should not be trusted everywhere.

Conditional access policies can evaluate device health, location, user risk, application sensitivity, and the context of the request. Managed devices provide an additional layer of accountability because the organization can establish which devices are permitted to access sensitive systems.

The fix is to require managed devices and stronger access conditions for high-value applications and data.

Leadership should ask whether the firm can answer these questions:

  • Can an employee access Microsoft 365 from an unmanaged personal device?
  • Does a sign-in from an unfamiliar country trigger investigation?
  • Are high-risk applications subject to additional authentication?
  • Are legacy authentication paths disabled?
  • Can the firm revoke sessions quickly across affected accounts?
  • Are token and session events connected to mailbox and file activity?

The goal is not to make normal work difficult. The goal is to reduce the value of a stolen session and create clear decision points when activity does not match the employee’s normal business context.

Payment changes require an independent control outside email

Email cannot be the sole approval channel for changes to vendor banking details.

If an attacker controls an employee’s session, they may control the conversation used to confirm the change. A second person reviewing the same compromised thread does not create independent verification.

The fix is dual approval with out-of-band verification.

Require two authorized people to approve payment detail changes. Confirm the change through a trusted phone number already maintained in the vendor record, not a number included in the email. For high-value payments, consider a documented callback process involving finance leadership.

This control protects revenue even when identity defenses do not prevent the initial compromise.

It also supports the broader vendor governance principles discussed in our [Vendor Risk Trap leadership post](https://www.oramca.com/blog/vendor-risk-trap-liability-2026). Security is strongest when business processes do not depend on a single identity, inbox, or approval path.

Employee training must address familiar document-share lures

Employees do not need to become cybersecurity analysts. They do need to understand that a familiar logo, notification style, or document-sharing workflow does not prove legitimacy.

The fix is practical training focused on decisions employees make every day.

Teach staff to pause when a message:

  • Requests a Microsoft 365 sign-in after clicking a document link.
  • Uses a DocuSign, HR, PTO, invoice, or secure-file-sharing theme.
  • Creates urgency around a payment, approval, or account issue.
  • Arrives from a familiar service but uses an unexpected domain.
  • Requests an MFA approval that was not initiated intentionally.

Employees should know how to report the message without fear of blame. A healthy reporting culture shortens the time between the first suspicious click and effective containment.

Executive oversight turns controls into resilience

Identity security is now a leadership issue because identity controls influence revenue protection, client trust, regulatory readiness, and operational continuity.

The fix is ongoing executive oversight.

At a minimum, leadership should receive regular reporting on:

  • Phishing-resistant MFA coverage for high-risk users.
  • Managed-device coverage for sensitive applications.
  • Active mailbox forwarding and rule exceptions.
  • Impossible-travel and anomalous sign-in investigations.
  • Session revocation testing and incident response timing.
  • Vendor payment verification compliance.
  • Employee reporting and training completion.

Our [Redtail breach analysis](https://www.oramca.com/blog/redtail-breach-ria-cybersecurity-blind-spot-wednesday-wisdom) makes a related point for wealth management firms: the most important security question is not whether a control exists. It is whether the firm can demonstrate that the control operates when the business is under pressure.

MFA remains necessary. It is no longer sufficient.

The modern strategy protects the full chain: the person, the device, the session, the mailbox, the application, and the business decision.

If your firm’s current answer is simply “we have MFA,” we recommend a practical conversation about what happens after MFA succeeds. We can help you identify which identities, sessions, mailboxes, and payment processes deserve priority and build a clear path toward stronger operational resilience.

Sources

  • [ANY.RUN: Mirage2FA phishing campaign targeting US organizations](https://any.run/cybersecurity-blog/mirage2fa-phishing-targets-us-companies/)
  • [The Hacker News: Mirage2FA surge hits 4,500 US and EU companies](https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html)
  • [The Hacker News: NovaCookies campaigns abuse genuine DocuSign notifications](https://thehackernews.com/2026/08/novacookies-campaigns-abuse-genuine.html)
  • [TrendAI: How AiTM phishing bypassed MFA to hijack a Microsoft 365 mailbox](https://www.trendaisecurity.com/en-us/resources-insights/trendai-security-blog/how-aitm-phishing-bypassed-mfa-to-hijack-a-microsoft-365-mailbox-in-bec-scheme)
  • [AssetMark privacy and security notices](https://www.assetmark.com/privacy-and-security/)
  • [AssetMark incident filing hosted by the Massachusetts Attorney General](https://www.mass.gov/doc/2026-962-assetmark-inc/download)

Oram Cybersecurity Advisors logo

Previous
Previous

Scam of the Week: This Text Is a Trick

Next
Next

Scam of the Week: Don't Bank on This Email