Passing the Login Test Does Not Mean You Let In the Right Person

Multi-factor authentication is a genuine security win, but organisations that mistake 'logged in successfully' for 'identity confirmed' are handing attackers a very comfortable seat at the table.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A corporate network access point with multi-factor authentication confirmation displayed on screen, showing successful login while simultaneously an attacker ga
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Multi-factor authentication, the system that asks for a second proof of identity beyond a password, does not by itself confirm who a person actually is.
  • Security teams that conflate three separate jobs, verifying identity, checking login credentials and spotting suspicious behaviour, risk waving attackers straight through.
  • Stolen session tokens and SIM-swapping attacks (where a criminal tricks a phone carrier into moving your number to their device) can defeat MFA without touching a password.
  • Organisations need continuous behaviour monitoring alongside login checks, not instead of them.

There's a comfortable lie that circulates in boardrooms after a company rolls out multi-factor authentication, often shortened to MFA. The lie: we have MFA, so we're safe from account takeovers. SecurityWeek flagged this gap recently, and it deserves unpacking for anyone who has been told MFA is the answer.

MFA is genuinely useful. Asking a user to confirm a login with a second step, a code from an app, a text message, a hardware key, makes life much harder for criminals who only stole a password. That's real protection. But "harder" is not "impossible."

So what does MFA actually miss?

MFA checks that someone controls a device or phone number. It doesn't check that the person holding that device is who they claim to be.

Session hijacking is one route around it. After a legitimate user logs in, their browser receives a small digital file called a session token that proves they're authenticated. Steal that token through a phishing page or malicious browser extension and an attacker walks straight into the account. The system sees a valid token and waves them through. We covered exactly this mechanism on 28 July in "Changing Your Password No Longer Kicks Hackers Out".

SIM-swapping is another route. A criminal calls a phone carrier, pretends to be the account holder, and persuades a customer-service agent to transfer the victim's phone number to a criminal-controlled SIM. Any MFA text message now goes to the attacker. Neither attack breaks MFA in a technical sense. Both render it irrelevant.

What should organisations actually do?

Three things need to happen: confirming who someone is before they get an account, checking credentials when they log in, and watching what they do once they're inside. Most companies invest heavily in the middle step and neglect the other two.

Identity verification, the upfront check that a new user is genuinely who they say they are, often amounts to little more than a working email address. Behaviour monitoring, flagging that a user who normally logs in from Manchester is suddenly downloading financial records from a Bulgarian IP address at 3 a.m., is expensive to build and easy to defer. As our 25 August story "Attackers Are Skipping the Login and Going After the Hiring Desk" found, identity verification is now the soft spot criminals probe first. The result here: a company can successfully authenticate an attacker while every log file shows a clean, legitimate login.

Should you worry?

If you receive an MFA code you didn't request, treat it as an emergency. Someone has your password and is trying to use it right now. Change it immediately and alert whoever manages your account.

For anything financial or medical, check whether the service offers app-based authenticator codes rather than SMS. App-based codes can't be intercepted by SIM-swapping.

MFA is a lock worth having. A determined burglar, though, studies the door too.

© 2026 Threat Vectr