MFA Alone Won't Save You: What Modern Attackers Know That Defenders Don't
A practitioner-focused webinar examines how threat actors sidestep conventional detection controls and why single-layer authentication is failing organizations.

Key points
- Adversary-in-the-middle phishing kits and session token theft have made MFA bypass a repeatable, low-friction technique.
- EDR and SIEM stacks built around payload detection routinely miss credential-based intrusions entirely.
- SEC disclosure rules require material incident reporting within four business days, a window that MFA-bypass incidents tend to compress through delayed detection.
- CIRCIA's reporting mandate for critical infrastructure remains pending after CISA published a proposed rulemaking in April 2024.
- FIDO2 and passkey implementations raise attacker costs meaningfully over push-based or TOTP methods, but aren't sufficient alone.
Does MFA still hold the line?
Attackers have methodically mapped the gaps. Phishing kits that sit between the user and the real site harvest session cookies in real time; MFA fatigue and SIM-swapping have matured into reliable techniques that treat MFA as a speed bump. The identity perimeter, once considered a solved problem after password-only auth fell out of favor, is now among the most actively targeted surfaces in enterprise environments. Our 28 May story "The Perimeter Is Gone. Attackers Already Knew That." made this case before it became conventional wisdom.
A webinar scheduled for today addresses exactly this shift, framing the session around how attackers currently evade detection tooling, why MFA implementations that met the bar two years ago may no longer be adequate, and what organizations can layer on top.
Should you worry about detection gaps?
The detection evasion angle is the sharpest part. EDR and SIEM logic built to flag known malware behavior routinely misses credential-based intrusions that never drop a payload. An attacker authenticating with a stolen session cookie looks, to most detection stacks, like a legitimate user. Log volume and alert fatigue compound the problem.
What do regulators expect?
Regulators have noticed. The SEC's cybersecurity disclosure rules, finalized in July 2023, require material incident disclosure within four business days. Incidents built on MFA bypass frequently involve delayed detection, which compresses that already-tight window considerably. Boards are asking questions that security teams haven't always had clean answers to.
CIRCIA will apply similar pressure to critical infrastructure sectors the SEC rules don't reach. CISA published a Notice of Proposed Rulemaking in April 2024; the comment period has closed and a final rule remains pending.
Common questions
What is phishing-resistant MFA?
FIDO2 and passkey implementations bind authentication to a specific device and origin, so a phishing kit that intercepts credentials can't replay them elsewhere. That's the distinction from push-based or TOTP methods, which an adversary-in-the-middle kit can still relay in real time.
What else needs to run alongside it?
Continuous authentication signals paired with device trust enforcement need to run alongside any MFA upgrade. Anomalous session detection closes the gap that even strong authentication leaves open once a valid session exists.
The blunt assessment from someone who has tracked this beat: the webinar's most useful function is probably forcing security teams to articulate their session-security posture to whoever signs the budget, because that conversation is overdue.


