The Phishing Attack That Beat MFA
Multi-factor authentication was turned on. The attacker got in anyway — no stolen-password alarm, no failed login, no alert. This really happened to a Central Florida business we work with. Every identifying detail has been removed, but the attack itself is exactly how it played out — because it’s a pattern every business owner needs to understand.
If your security plan is “we have MFA, so we’re covered,” this is the story that changes it.
How the attack worked
It started the way these always do — with one email that looked completely routine:
- The bait. An employee received a “review and sign” message. The link led to a pixel-perfect Microsoft sign-in page.
- The mirror. That page was fake, and it sat in the middle — secretly relaying everything she typed straight to the attacker in real time. Security teams call this an “adversary-in-the-middle” attack.
- The handoff. She entered her password and approved the MFA prompt, just like any other day. But the attacker wasn’t after her password — they captured the live session the login handed back. From that moment, they were her.
- The quiet login. The attacker signed in from rented servers in other states, at the same time as her real session. MFA was already satisfied, so nothing failed and nothing alerted.
- The backdoor. Within minutes, they registered their own authenticator on the account — so even a password reset wouldn’t lock them out.
- The payload. They sent roughly 200 spam emails from the trusted account, then deleted them from the Sent folder so no one would notice.
The only reason anyone caught it? Microsoft’s own spam filter eventually blocked the account from sending. That blunt, late signal was the sole tripwire that fired.
Why MFA didn’t stop it
Traditional MFA proves who you are at the moment you log in. This attack never fought the login — it stood in the middle and stole the result. Once the session is taken, the attacker inherits the entire authenticated session, MFA and all.
That’s the uncomfortable truth: “We have MFA” is no longer a finish line. Against modern phishing, it’s the starting line.
How we proved it — the forensic trail
None of this was guesswork. We reconstructed the entire attack from the account’s own sign-in and audit records. Three pieces of evidence told the whole story.
1. The sign-in logs — one account, three cities, the same hour.
| Time (UTC) | IP address | Location | Result | |
|---|---|---|---|---|
| 14:01 | 153.75.87.53 | Atlanta, FL area | ✓ Success | the employee |
| 14:28 | 172.81.130.251 | Rye, NY | ✓ Success | attacker (datacenter IP) |
| 16:30 | 172.81.61.146 | Chandler, AZ | ✓ Success | attacker (datacenter IP) |
The account was signed into from the employee’s real location and, at the same time, from rented datacenter IPs in two other states. Every login shows “Success” — because MFA had already been satisfied. Nothing failed, so nothing alerted.
2. The audit log — the moment of persistence. At 14:01:50 UTC, a single entry: UserAuthMethod.SoftwareOathProofupRegistration — success, initiated from the attacker’s IP. That one line is the smoking gun: the attacker registering their own authenticator, giving themselves a way back in even after a password reset.
3. The outbound counters — the only signal that fired. In 24 hours, 200 of 210 messages from the account were flagged as spam — a 95% spam rate. That tripped Microsoft’s send-block (550 5.1.8 — bad outbound sender) and, hours late, finally made the compromise visible.
This is the difference between “we think you were phished” and knowing exactly what happened, when, and from where — which is what lets us contain an attack completely instead of hoping we got it all.
How we shut it down — the same day
With the timeline in hand, our team:
- Revoked every session, reset the password, and removed the attacker’s authenticator — cutting off both access and persistence.
- Swept for the rest: inbox rules, mail forwarding, app permissions, and every other account in the company. No spread.
- Restored normal mail flow and documented the full incident.
Start to finish: contained the same day.
What actually protects your business
Catching an attack quickly is good. Not being catchable is better. Three layers would have stopped this one cold:
- Managed email security. The phishing email never reaches the inbox — the lure is quarantined before anyone can click.
- Phishing-resistant MFA. Passkeys and hardware keys can’t be relayed by a middle-man. The stolen-session trick simply doesn’t work against them.
- Monitored response. Your earliest warning shouldn’t be Microsoft blocking your mail. The right signals, watched closely, mean minutes — not weeks.
The takeaway
Phishing has evolved past the point where MFA alone is enough. The businesses that stay safe aren’t the ones with a single checkbox — they’re the ones with layers, and someone watching.
Want to know how your business would hold up against an attack like this? iTech Plus offers a straightforward email-security check-up — no jargon, no pressure. Call us at (321) 221-7117 and we’ll walk through exactly where you stand.
