MFA fatigue and stolen session tokens
Multi-factor authentication stopped password reuse cold, so attackers stopped attacking the password. Two techniques that get past MFA, and what actually closes them.
MFA fatigue
Having stolen a valid password, the attacker triggers repeated push prompts — sometimes alongside a call posing as IT — until the user approves one just to make it stop. It defeats the weakest and most common form of MFA: the simple approve/deny push.
Session-token theft
Even strong MFA issues a session token once you are in. Infostealer malware lifts that token from the browser; the attacker replays it and is inside without ever seeing your password or your MFA prompt. This is why a credential you never issued — a session cookie — can be the entire breach.
What closes it
Move to phishing-resistant MFA such as FIDO2 or passkeys, or at least number-matching. Shorten session lifetimes and bind tokens to a device where you can. Add detection for anomalous token use and impossible travel. And monitor the dark web for your exposed credentials and tokens, so a silent compromise becomes an early warning instead of a breach notification.
Questions, answered
Does any MFA stop this?
How would we know a token was stolen?
Where this goes next
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.