Security researchers tracked a 1,380% jump in phishing kits built to slip past multi-factor authentication over the past year. That number should stop any owner who flipped on MFA and mentally checked the box. The protection is still worth having. It just stopped being the finish line.
Here’s the uncomfortable part. Most small businesses treated MFA as a one-time switch. Turn it on, tell people to approve the prompt, move on. Attackers noticed. They quit guessing passwords and started stealing the thing MFA hands you after you sign in: the session. Once they hold that, the six-digit code you typed doesn’t matter anymore. This post walks through why that gap opened, which MFA methods still hold, and what a Florida small business should actually change this quarter.
How Are Phishing Kits Getting Past MFA?
Modern kits use an attacker-in-the-middle page that sits between your employee and the real login screen. The fake page relays every keystroke to the genuine site in real time, including the MFA code. When the real site issues a session cookie, the kit grabs it. The attacker replays that cookie and is now logged in as your employee.
The old mental model was that a stolen password was useless without the second factor. That held for years. It doesn’t hold against a proxy that harvests the factor and the resulting session in one motion. The employee did nothing obviously wrong. They approved a prompt for a login they believed they had started.
Picture the sequence from your bookkeeper’s chair. An email says a shared invoice needs review. She clicks, lands on what looks exactly like the Microsoft 365 sign-in, enters her password, and approves the push on her phone. The page then forwards her to the real document, or to a bland “session expired” screen. Nothing looks broken. Behind the glass, the attacker’s proxy already copied her live session and is reading her inbox. No malware ran. No alarm fired on her laptop.
Why the lure works so well now
These kits ship as ready-made services. A low-skill criminal rents one, points it at a cloned Microsoft 365 or Google Workspace login, and blasts it out. The landing pages are pixel-accurate. And the email that carries them keeps getting better, which is exactly how convincing today’s phishing emails have become. A believable email plus a perfect fake login is a hard combination for a busy employee to catch mid-morning.
The tell is subtle. The address bar shows a lookalike domain, off by a character or a hyphen. Nobody checks the address bar when they think they clicked their own calendar invite. That’s the whole business model. The FTC’s plain-language guide on how to recognize and avoid phishing scams still applies here, but the newer twist is that spotting the bad email is only half the job now.
Does Turning On MFA Still Protect Your Business?
Yes, keep it on. MFA still blocks the overwhelming majority of automated attacks, including password spraying and credential stuffing from old breaches. The point isn’t that MFA failed. It’s that not every MFA method carries the same weight, and the weakest ones are exactly what most small teams enabled first.
SMS codes and simple approve-or-deny push prompts are the softest. A text code can be relayed through a proxy just like a password. A push prompt can be worn down by “MFA fatigue,” where an attacker who already has the password fires prompts at 2 a.m. until someone taps approve to make their phone stop buzzing. Both are far better than nothing. Neither is designed to survive a determined proxy.
Owners assume they’re covered because the dashboard says MFA is enabled. That status line is honest and incomplete. It confirms a second factor exists. It says nothing about whether that factor can be relayed, and it says nothing about the fifteen third-party apps your team logs into that never asked for MFA at all. The gap usually lives in those quieter corners, not the obvious front door.
Where monitoring earns its keep
Even a stolen session leaves tracks. A login from a new country minutes after a normal one in Florida is an impossible-travel signal. A new mail forwarding rule appearing right after sign-in is a classic post-compromise move. Catching those in the first hour is the difference between a scare and a wire-fraud loss, and it’s the layered monitoring a managed security program watches for around the clock. Alerts only help if someone is actually reading them.
What Does Phishing-Resistant MFA Actually Look Like?
Phishing-resistant MFA ties the login to the real website’s identity, so a proxy can’t relay it. The two mainstream forms are passkeys (built into modern phones and laptops) and physical security keys (FIDO2 hardware you tap or plug in). Both refuse to authenticate to a lookalike domain, which is the exact trick these kits depend on.
The reason they hold is a cryptographic bond. The passkey or key checks the domain it’s talking to and signs a challenge only the genuine site can verify. NIST’s standards body defines this property directly in its glossary entry for phishing resistance, and it’s why a relayed prompt simply fails instead of handing over a session. There’s no code to read aloud, retype, or leak.
You don’t have to convert everything at once
Start with the accounts an attacker wants most. That’s your email admins, your finance approvers, and anyone who can move money or change payroll. Put phishing-resistant MFA on those first. Layer it with strong inbound filtering, because email security controls that flag lookalike login pages stop many of these lures before an employee ever sees them. Passwords, prompts, and passkeys can coexist while you roll it out in stages.
What Should Your Small Business Do This Quarter?
Treat this as a short, concrete project, not a policy memo. In one quarter a small business can inventory its MFA methods, upgrade the high-value accounts to phishing-resistant options, turn on session and sign-in alerting, and run one honest training session. That sequence closes the biggest part of the gap without disrupting the whole team.
Step one is an inventory nobody enjoys. Which accounts have MFA, and which method? Most owners are surprised to find a few finance logins still running on SMS or, worse, no second factor at all. Document it. You can’t harden what you haven’t listed.
Step two is turning on the alerting that most platforms already include but leave dark. Microsoft 365 and Google Workspace can flag risky sign-ins, new forwarding rules, and impossible-travel logins out of the box. The setting exists. Someone has to switch it on, route the alerts to a person who reads them, and decide what happens when one fires. An alert nobody sees is the same as no alert.
The human layer still matters
Passkeys shrink the attack surface, but people still make judgment calls on links and prompts every day. A short, plain briefing beats an annual slideshow: show staff a real lookalike domain, explain why an unexpected prompt should be denied and reported, and make reporting painless. Pairing that with ongoing security awareness training for your staff turns your team from the soft spot into an early-warning system. One employee who reports a weird prompt can save the whole company a very bad week.
Frequently Asked Questions
Can hackers really bypass multi-factor authentication?
Yes, but not by breaking the math. They use a proxy page that sits between the employee and the real login, relaying the code in real time and stealing the session cookie the site issues afterward. Phishing-resistant methods like passkeys and security keys defeat that technique because they refuse to authenticate to a fake domain.
Is SMS-based MFA still worth using?
It’s better than a password alone, so don’t rip it out with nothing to replace it. But SMS codes can be relayed through a phishing proxy and are also exposed to SIM-swap fraud. Move your highest-value accounts to passkeys or hardware keys, and keep SMS only as a fallback where nothing stronger is available.
What is a passkey, in plain terms?
A passkey is a login credential stored on your phone or laptop that unlocks with your fingerprint, face, or device PIN. There’s no code to type and nothing to phish. It only works on the genuine website it was created for, which is what makes it resistant to the lookalike-domain trick these kits rely on.
How do I know if an account was already compromised this way?
Look for the aftermath: unfamiliar sign-in locations, new mail-forwarding or inbox rules you didn’t create, and messages in your Sent folder you don’t recognize. Any of those warrant an immediate password reset, a revoke of active sessions, and a review of recent account changes. Continuous sign-in monitoring catches these signals far sooner than a person scanning logs once a week.
Does antivirus or a firewall stop this kind of attack?
Not on their own. This attack targets the login flow in a browser, not the endpoint, so traditional antivirus often sees nothing malicious. The real defenses are phishing-resistant MFA, inbound email filtering that blocks the lure, and monitoring that flags the suspicious session. Layers matter because no single control catches every step.
How much of this can a small team realistically handle?
More than you’d think, in stages. Turning on stronger MFA for a handful of critical accounts and enabling sign-in alerts are low-cost, same-week changes. The heavier lift is doing it consistently across every app and keeping watch afterward, which is where a managed provider usually carries the load so your team can stay focused on the business.
Ready to Close the MFA Gap Before It Costs You?
If you’re not sure which of your accounts still rely on a phishable code, that uncertainty is the risk. O&O Systems works with small businesses across Florida to inventory MFA methods, roll out phishing-resistant logins on the accounts that matter, and keep sign-in monitoring running so a stolen session gets caught fast. The best first move is to schedule a security risk assessment and see exactly where the gaps are. Turning MFA on was the right start. Closing this gap is the part that keeps a bad email from becoming a bad quarter.