Skip to content
Back to Blog
5 min readphishingMFAtrend

The Rise of AiTM Phishing: Bypassing MFA at Scale

Adversary-in-the-middle (AiTM) phishing attacks have become the dominant method for bypassing multi-factor authentication. Here's what we're seeing in the field.

What is AiTM phishing?

Unlike traditional phishing that simply steals credentials, adversary-in-the-middle (AiTM) phishing sets up a proxy between the victim and the legitimate login page. The victim interacts with the real site through the attacker's proxy, which captures both the credentials and the session cookie generated after MFA verification.

This means that even organizations with strong MFA deployed can be compromised. The attacker doesn't bypass MFA technically: they let the user complete it and then steal the authenticated session.

What we're seeing in the field

In 2026, we've responded to a significant increase in AiTM-based compromises. Common patterns include phishing emails disguised as Microsoft 365 login notifications, fake document sharing links that redirect through AiTM proxies, QR code phishing ('quishing') that sends users to AiTM pages on mobile devices where URL inspection is harder, and increasingly convincing clone pages that are nearly indistinguishable from legitimate Microsoft login flows.

The toolkits behind these attacks (like EvilProxy and Tycoon 2FA) are now available as services, lowering the barrier for attackers.

How to defend against AiTM attacks

Implement phishing-resistant MFA methods such as FIDO2/WebAuthn hardware keys or Windows Hello for Business. These methods use cryptographic binding to the legitimate site, making AiTM proxying ineffective. Configure conditional access policies to require compliant devices and block legacy authentication. Implement token protection policies in Azure AD to bind session tokens to specific devices. Deploy advanced anti-phishing solutions that can detect AiTM proxy infrastructure. Train users to recognize the subtle signs of AiTM phishing.

Talk to a senior responder about The Rise of AiTM Phishing: Bypassing MFA at Scale.

Schedule a response call
Incident response

Need incident response?

088 SECDESK (7323375)

Call us. A senior responder picks up.

  • Two-hour SLA
  • Dutch senior responders

Emergency form

Two-hour response.

Is this urgent? Call us.

088 SECDESK (7323375)

Cannot wait? Call 088 SECDESK (7323375) now

Emergency line088 SECDESK
Call now