#mfa-bypass
6 articles
Business services and enterprise organizations were the primary targets in the nine high-severity incidents tracked under the mfa-bypass tag between April and August 2026. Global operations, particularly those in Canada and North America, faced the most significant impact. Storm-2755 and Tycoon 2FA were observed as separate threat actors in these campaigns. The affected sectors included finance and financial services, alongside the broader business services and enterprise categories. All reported cases were rated high severity, underscoring the consistent risk posed to authentication systems across these regions and industries.
HIGHGitHub Pages, Cloudflare Workers Fuel MFA-Bypass Phishing
Kaspersky details a cloud-based AitM phishing campaign abusing GitHub Pages and Cloudflare Workers to bypass MFA via service workers and Ultraviolet proxy.
HIGHDeepfake Voice Attacks Outpace Defenses, Bypass MFA
Adaptive Security finds 3 seconds of audio enough to clone a voice for fraud; deepfake calls tricked employees into wiring $243K in one case. No detection tool caught the attack.
HIGHTycoon 2FA Phishing Kit Disruption Fuels Surge in Copycat Attacks
The disruption of the Tycoon 2FA phishing-as-a-service platform has led to a surge in copycat attacks, as threat actors reuse its tools and techniques in other kits, increasing the overall volume of multi-factor authentication bypass attempts.
HIGHTycoon 2FA Phishing Group Shifts to Device Code Attacks
The Tycoon 2FA phishing group has abandoned its namesake toolkit, adopting device code phishing to bypass multi-factor authentication and compromise Microsoft 365 and Gmail accounts.
HIGHAttackers Shift from Phishing to Social Engineering for Okta Compromise
Threat actors are bypassing email security by using phone-based social engineering to target IT help desks and compromise Okta identity systems, enabling initial access to corporate networks.
HIGHStorm-2755 Hijacks Payroll via AiTM Attacks
Financially motivated group Storm-2755 targets Canadian employees using AiTM session hijacking to redirect salary payments.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.