Video
MFA Is Not Enough
Published August 24, 2026
About This Video
In this Episode I talk about why having MFA enabled is NOT enough anymore and how attackers are bypassing it. Additional layers and visibility into your environments is more important than ever.
#SouthwestNetworksIncPalmDesert
➡ Download our Free IT Buyers Guide: https://www.southwest-networks.com/it-buyers-guide
➡ Interested in working with us, book a quick and easy call: https://www.southwest-networks.com/discoverycall
Connect with us!
https://www.southwest-networks.com
https://www.facebook.com/southwestnetworks
https://www.linkedin.com/company/southwest-networks-inc
⏰ Timecodes ⏰
00:00 Introduction
00:30 Attackers trying to bypass MFA right now
01:05 Attack Method 1
01:48 Password Spray Attack
02:38 Why this scares me
03:22 Attack Method 2
04:18 Once attackers gain access
05:25 Is MFA enabled? Is it the right type of MFA?
05:46 Who is monitoring your envirionment?
Full Transcript
Auto-generated from the video's captions. Minor transcription errors may exist.
Welcome back to another episode of Cappuccino Chat. This time we're talking about why MFA isn't enough anymore and how attackers are bypassing it right now. Okay, this time we're talking about why MFA isn't enough anymore, even if you have it enabled, which hopefully you do, and how attackers are bypassing it right now. So now something that should kind of get your attention and it cuz it got mine is attackers are currently running active campaigns to break into Microsoft 365 accounts. Even with the MFA enabled. Now this shouldn't come as a surprise, Microsoft's a big target, but now they figured out how to bypass the MFA that some, not all, small businesses have enabled on their accounts. Now this isn't just a hypothetical. In July, which was just the other month, threat intelligence identified specific toolkits that these attackers can download for, you know, from the dark web and use that are built specifically to steal authentication tokens after MFA is approved. So let me kind of explain this to you what the authentication token is. So you're directed to what looks like a legitimate website. You log in with your Microsoft account password and then you enter your MFA code. It approves the request. That's it. Looks, sounds normal. You've probably done it a million times, but because you were redirected through a attacker's website, they now have your token. They've used that toolkit and they've grabbed the token. That token now allows them to log in to your account without even prompting you to let you know somebody else is trying to log in that hey, you got to enter your MFA code. Cuz they have that token, that's good. Separately, they're also still using automated password spraying tools that they cycle through credentials. Maybe they've got a hold of some credentials on the dark web. There's a big old dictionary of passwords out there that they'll cycle through and they'll try thousands of combinations against your Microsoft 365 login without triggering any lockouts that most people might assume it would stop them. They don't always and they know what those triggers are and they do their best to stay under them and then come back and try again. So now I'll be honest. When I saw these reports, I was like, "Yeah, no big deal. I mean, MFA, everybody's got it. It's not a big deal. We've got some extra protection for our clients. We've known about this being an issue, but what scared me more uh than what I've been reading in a while is well, we still talk to businesses and prospects that don't have MFA enabled at all. They don't see the reason for it. They don't think it's needed. They don't want to be bothered to enter an extra code. So there are some ways to enable things and protect your site with MFA without being so annoying, if you will. So learning that attackers now have reliable tools to bypass even MFA, which we've been talking to everybody about when it's enabled, we've got this now, too, cuz now they found a way to do that. So now they're stealing passwords. Now they know how to steal your MFA if a end user is fooled into doing it. And this is just a compounding problem for everybody. So let me explain another kind of attack. The attacker gets your credentials, maybe from a data breach, no fault of your own, no fault of any employees. Uh you were never notified about it or because someone on your team reused the password from another account, right? So they try to log in your Office 365. MFA prompts your employee. The employee ignores it. Hey, I'm not at my computer. I'm going to ignore it. The attacker prompts again and again and again. At some point, because people are just busy and tired of their phone notifying them to log in and assuming maybe it's their computer it's that time again they need to log in they finally hit approve just to make it stop. This kind of attack is called MFA fatigue and it's just one of the most effective attacks happening right now because it doesn't require breaking technology it just requires wearing a person down. Right? We're all busy our phone constantly dinging and going off we just want to get make it make it stop. Now once they're in the attacker has access to everything connected to that account. So email OneDrive SharePoint your Teams account all of it contacts right? For a medical practice that could be patient information. For a CPA firm that's client possible financials tax return information might be stored there because you're going back and forth with asking some questions account numbers maybe hopefully not right? Hopefully all this stuff was properly sent using encrypted emails but you never know. And for any small business it's potentially years of data if you don't catch it quickly. Now some of that exposure is simply unrecoverable. You can't get it back right? The attacker reads your conversation learns how your billing works sets up silent email forwarding so they keep receiving your mail even after you change your password. And then it moves quietly until they're ready to do something visible. By then the damage is already done. So this is too late. So even if somebody does bypass your MFA what else kicks in to help right? We'll we'll get to that in a second. So now if your IT person has told you we have MFA we're covered. You need to dig a little deep. Need to push back a little bit. First what kind of MFA are you using? Text message and phone is currently being gone away in the Microsoft world. Some of you may have even gotten the alert from Microsoft saying hey you need to stop using this method of authentication. It's no longer secure. Second who gets notified if someone starts running a password spray attack against your accounts? Who gets notified if a email forwarding rule gets set up? If the answer is I'm not sure or nobody, nobody monitors that, then you have a visibility gap, not a technology gap. And visibility is what determines whether a breach gets caught in minutes, hours, or weeks. Now, this is one of those situations where checking a box, enabling MFA, isn't the same as being protected. MFA was the right answer for a very long time. It's still a necessary layer, but it's not all that's needed anymore. You need additional layers. So, here at Southwest Networks, we have additional layers in that email chain to help identify these types of attacks. So, if somebody does wear an employee down and get into their account, we get alerted. We can stop these accounts takeovers in minutes, not weeks or months. So, if you want to discuss how to review where your security currently stands right now, please give our office a call at 760-770-5200.