Home / Companies / WorkOS / Blog / Post Details
Content Deep Dive

How attackers are bypassing MFA using AI in 2026

Blog post from WorkOS

Post Details
Company
Date Published
Author
Maria Paktiti
Word Count
1,654
Company Posts That Month
65
Language
English
Hacker News Points
-
Post removed?
No
Summary

Multi-factor authentication (MFA) has long been a cornerstone of digital security, blocking 99% of automated attacks, but evolving threats have exposed its vulnerabilities, necessitating a shift in strategy. Attackers are increasingly targeting session tokens, using Adversary-in-the-Middle (AiTM) attacks to bypass MFA by capturing session cookies in real-time, facilitated by commercial tools like EvilProxy and Tycoon 2FA available on platforms like Telegram. With the integration of AI, attackers can automate reconnaissance, craft highly convincing phishing emails, and use deepfakes for voice phishing, significantly enhancing the efficacy of their campaigns. Despite these advancements, MFA remains a critical security measure, but it must be implemented with phishing-resistant methods like FIDO2 security keys, and complemented by continuous session management and OAuth governance. The persistence of legacy fallback methods, inadequate session security, and lack of updated training contribute to the gaps in current MFA deployments, underscoring the necessity for organizations to adapt their strategies to address these sophisticated threats.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Real-time 4 6,296 1,346 246 -2%
LLM 1 5,932 1,046 223 -2%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.