Multi-factor authentication was enabled on 59% of the accounts attackers successfully took over in 2025, according to Proofpoint, and Obsidian Security found that MFA failed to prevent the attack in 84% of its incident responses. The number that used to end an intrusion, a login protected by a second factor, no longer does. Attackers have moved down the stack from the password to the session: they let the victim complete a genuine MFA login, then steal the authenticated session token that the identity provider issues afterward. SpyCloud recaptured 8.6 billion stolen session cookies and session artifacts in 2025 alone. When the token is the target, the second factor is already behind the attacker.
Three forces define MFA bypass in 2026. Adversary-in-the-middle (AiTM) phishing relays the real login through a reverse proxy and captures the session cookie in transit, and Proofpoint reports that Tycoon 2FA alone became the highest-volume AiTM phishing service in its visibility. Infostealer and session-cookie theft turns any malware-infected browser into a set of ready-made authenticated sessions, which is why SpyCloud now sees more session artifacts than passwords in modern phishing datasets. Device code phishing abuses a legitimate OAuth flow so that even passkeys pass cleanly, and Push Security measured device code phishing pages rising 37.5 times in the first four months of 2026. This reference serves CISOs, identity and security engineers, and the journalists who cite these numbers.
This post is the Stingrai research team's canonical 2026 reference for MFA bypass, AiTM, and session-token theft. It aggregates the figures a writer would otherwise chase across a dozen reports, drawing on primary data from Microsoft, Mandiant, Proofpoint, SpyCloud, Verizon, IBM, Cisco Talos, Push Security, Huntress, Cofense, Zscaler, CISA, and the FIDO Alliance. Lead data is full-year 2025 telemetry, the freshest available, because the major identity and breach publishers have not yet released full-year 2026 reports as of August 2026; the fastest-moving 2026 signals, such as device code phishing growth, are labeled with their measurement window. Every stat below carries its source, year, and methodology context so any claim can be audited against its primary publisher.
Key MFA bypass and AiTM statistics at a glance (2026)
MFA-enabled accounts still taken over (2025): 59% of successfully compromised accounts had MFA turned on (Proofpoint).
MFA failed in incident response (2025): 84% of Obsidian incident responses saw MFA fail to prevent the attack (Obsidian Security).
Stolen session cookies recaptured (2025): 8.6 billion session cookies and session artifacts (SpyCloud).
Daily identity attacks (2025): more than 600 million per day, with roughly 7,000 password attacks blocked every second (Microsoft).
Phishing-resistant MFA effectiveness: blocks over 99% of identity-based attacks (Microsoft Digital Defense Report 2025).
Successful account takeover (2025): 67% of organizations suffered at least one successful account takeover (Proofpoint).
Device code phishing growth (2026): phishing pages up 37.5x by April 2026 (Push Security); detections up 1,380% (Huntress).
Successful phishing growth (2025): up 400% year over year in SpyCloud data, with the workforce three times more likely to be hit by phishing than by infostealer malware (SpyCloud).
Most expensive breach entry point (2026): phishing and its voice and SMS variants, at an average of US$5.29 million (IBM Cost of a Data Breach Report 2026).
Passkeys in use (2026): roughly 5 billion worldwide, with 75% of people having enabled at least one (FIDO Alliance).
Key takeaways
MFA is not failing because the factor is weak; it is being skipped entirely. AiTM phishing, cookie theft, and device code phishing all wait for a genuine, successful MFA login and then take the session that follows. That is why 59% of taken-over accounts had MFA on (Proofpoint) and why Obsidian saw MFA fail in 84% of its incident responses. The control worked; the attacker moved to a layer the control does not protect.
The stolen session token is the new stolen password. SpyCloud recaptured 8.6 billion session cookies and session artifacts in 2025 and reports that modern phishing datasets now routinely bundle cookies, tokens, and MFA workflow data alongside credentials. Mandiant's M-Trends 2026 describes the same shift on the frontline: attackers harvesting long-lived OAuth tokens and session cookies to inherit access rather than re-authenticate.
Volume and impact point in opposite directions, and that is the trap. Microsoft still sees the overwhelming majority of its 600-million-a-day identity attacks as simple password spray and brute force. AiTM and token theft are a small slice of raw volume, but they are the slice aimed squarely at the accounts that already have MFA, so they carry disproportionate impact. Judging the threat by raw attack counts understates it.
Device code phishing is the fastest-moving MFA bypass of 2026, and it defeats passkeys. Because the victim completes a real login on the real identity provider, a passkey works exactly as designed and the attack still succeeds. Push Security measured a 37.5x rise in device code phishing pages by April 2026, and Huntress tracked a 1,380% jump in detections and 344 organizations hit in a single wave.
Phishing-resistant MFA is the one control that reverses the math. Microsoft reports that phishing-resistant MFA blocks over 99% of identity-based attacks, and CISA names FIDO/WebAuthn as the only widely available phishing-resistant method. The FIDO Alliance counts roughly 5 billion passkeys now in use. The catch is enforcement: weak fallbacks and post-login authorization flows still leave gaps that statistics-literate defenders should plan for.
Methodology
This reference aggregates figures published by primary sources between January 2025 and August 2026. The lead identity and breach datasets are full-year 2025 telemetry, because the major annual reports covering full-year 2026 had not been released as of the August 2026 research cutoff. The fastest-moving 2026 indicators, such as device code phishing growth, are stated with their exact measurement window rather than annualized.
Primary sources used, with publication timing and data window in parentheses: the Microsoft Digital Defense Report 2025 (published October 2025) and the Microsoft Security Blog (2025); Mandiant M-Trends 2026 (published March 2026, drawing on more than 500,000 hours of 2025 incident response); the Verizon Data Breach Investigations Report 2026; the IBM Cost of a Data Breach Report 2026 (published July 2026); Proofpoint threat research and State of the Phish data (2025 to 2026); the SpyCloud 2026 Annual Identity Exposure Report (2025 data); Cisco Talos and Cisco Duo telemetry (2025 to 2026); Push Security and Huntress device code phishing research (2026); Cofense annual email security data (2024 to 2025); Zscaler ThreatLabz phishing research (2025 to 2026); CISA phishing-resistant MFA guidance; and the FIDO Alliance World Passkey Day 2026 research (11,000 consumers and 1,400 enterprise decision-makers across ten countries).
Every figure is attributed inline to a named primary publisher and linked to its source. Where a widely repeated number could not be traced back to the original publisher on at least one verification pass, it was dropped rather than estimated or laundered through a secondary article. Figures reported in a foreign currency are noted as such; all dollar figures in this post are US dollars as reported by the source.
How common are MFA bypass attacks in 2026?
MFA bypass is no longer an edge case; it is the default assumption for account takeover against a defended target. The clearest single measurement comes from Proofpoint, which reports that in 2025, 99% of organizations faced account-takeover attempts, 67% suffered at least one successful account takeover, and 59% of the accounts that were actually taken over had MFA enabled at the time. In other words, MFA being present was the norm among victims, not a differentiator.

Incident-response data tells the same story from the responder's chair. Obsidian Security found that MFA failed to prevent the attack in 84% of its incident responses, alongside a 300% year-over-year surge in SaaS breaches and a fastest observed time from initial access to data exfiltration of just nine minutes. The lesson is not that MFA is worthless. It is that the presence of MFA has stopped predicting whether an account survives.
There is an important nuance that keeps this post honest, and it is one that careless coverage gets wrong. By raw volume, MFA bypass is still a minority technique. Microsoft sees more than 600 million identity attacks a day and blocks roughly 7,000 password attacks every second, and the overwhelming majority of that traffic is unsophisticated password spray and brute force against accounts that often have no MFA at all. AiTM and token theft are a small fraction of that firehose. But they are the fraction deliberately aimed at the hardened accounts, the ones where MFA is already on, so their share of raw attempts understates their share of consequential breaches. Microsoft's own security researchers note the direction of travel plainly: as MFA adoption grows, AiTM credential phishing increases. Attackers invest in bypass precisely where MFA has raised the cost of everything else.
What is an adversary-in-the-middle (AiTM) attack?
An adversary-in-the-middle attack places an attacker-controlled relay between the victim and the real identity provider. The victim clicks a phishing link, lands on a reverse proxy that mirrors the genuine login page in real time, and enters their username, password, and second factor. Every one of those is transparently forwarded to the real service, so the login genuinely succeeds. The identity provider then issues a session cookie to confirm the authenticated session, and the relay copies that cookie. The attacker replays it and is now inside the account without ever knowing the password's long-term value or defeating a single MFA factor, because the victim performed the MFA for them.
This is why AiTM is categorized as a session hijacking technique rather than a credential-phishing technique. The credential is almost incidental. The prize is the post-authentication session token. AiTM is delivered at scale through phishing-as-a-service (PhaaS) kits that package the reverse proxy, the lookalike pages, and the cookie capture into a subscription product. Proofpoint reports that Tycoon 2FA became the highest-volume AiTM phishing threat in its visibility, harvesting Microsoft 365 and Gmail session cookies to achieve full account takeover even where MFA is enabled. Cisco Talos documents the wider kit ecosystem, including Tycoon 2FA, Rockstar 2FA, EvilProxy, Greatness, Mamba 2FA, and the long-running open-source Evilginx framework. Zscaler ThreatLabz notes that the newest kits combine AiTM with browser-in-the-middle (BiTM) techniques to capture credentials and MFA codes inside the active login flow, turning a single click into session-level compromise.
For a defender-focused walkthrough of how to spot AiTM in identity logs and cut a hijacked session mid-flight, see the Stingrai analysis of adversary-in-the-middle phishing detection. This post is the statistics companion to that guide.
Session hijacking and token theft: the new account-takeover currency
If AiTM is one way to obtain an authenticated session, infostealer malware is the other, and it operates at a scale that reframes the whole problem. SpyCloud's 2026 Annual Identity Exposure Report recaptured 8.6 billion stolen cookies and session artifacts exposed through malware infections, part of a recaptured datalake that grew 23% in a year to 65.7 billion distinct identity records. SpyCloud also recaptured 642.4 million exposed credentials from 13.2 million infostealer infections in 2025, an average of roughly 50 credentials per infected device. Critically, SpyCloud reports that successful phishing rose 400% year over year and that modern phishing datasets increasingly ship with session cookies, authentication tokens, and even MFA workflow data bundled alongside the passwords, so an attacker can assume an authenticated session without ever tripping a login-based alert.
The frontline incident data agrees. Mandiant's M-Trends 2026, built on more than 500,000 hours of 2025 incident response, describes attackers routinely harvesting long-lived OAuth tokens and session cookies and stealing hard-coded keys and personal access tokens to maintain access. The same report shows how fast this economy now moves: the median time for an initial-access broker to hand off a foothold to the next actor has collapsed to 22 seconds. A stolen token is liquid, and it changes hands almost instantly.
Token theft matters because a session cookie carries the completed MFA claim with it. Once the token is replayed, the account behaves as fully authenticated. There is no second prompt, no push notification, and often no anomaly at the login layer at all, which is exactly why detection has to move to the session and identity layers rather than watching failed logins.
How attackers defeat MFA: the 2026 technique breakdown
The techniques below all share one property: they succeed after a legitimate authentication, or they sidestep the factor's delivery channel entirely. That is what separates 2026's account-takeover playbook from the credential-stuffing era.
MFA-bypass technique | How it defeats the second factor | Representative 2026 data point (source) |
|---|---|---|
AiTM / reverse-proxy phishing | Relays the real login and steals the post-MFA session cookie in transit | Tycoon 2FA is the highest-volume AiTM phishing service in Proofpoint's visibility (Proofpoint) |
Infostealer session-cookie theft | Malware exfiltrates live session cookies and tokens from the browser | 8.6 billion stolen cookies and session artifacts recaptured in 2025 (SpyCloud) |
Device code phishing | Victim completes a real MFA login; attacker collects the issued OAuth tokens | Device code phishing pages up 37.5x by April 2026 (Push Security) |
OAuth consent phishing | User grants a malicious app standing token access after a genuine login | Malicious apps impersonated more than 50 brands and succeeded in over half of targeted environments (Proofpoint) |
Help-desk and MFA-reset social engineering | Attacker convinces support to reset or re-enroll MFA, or resets it directly | UNC3944 targets IT help desks to bypass MFA; voice phishing is now the number two intrusion vector at 11% (Mandiant M-Trends 2026) |
MFA fatigue / push bombing | Repeated approval prompts until the user accepts one | Named by CISA among the primary MFA-bypass methods requiring number matching as a control (CISA) |
SIM swap and SS7 interception | Hijacks the SMS or voice channel that delivers one-time codes | Listed by CISA alongside phishing and push bombing as a core MFA-bypass method (CISA) |
Table 1: How attackers defeat MFA in 2026, with a representative primary-sourced figure per technique.
Two structural points fall out of this table. First, four of the seven techniques (AiTM, cookie theft, device code, and consent phishing) never touch the factor at all; they operate on the session or the authorization grant that exists after MFA has already passed. Second, the two that do target the factor's delivery, push bombing and SIM swap, are exactly the ones CISA singles out as reasons to move off SMS and simple push toward phishing-resistant methods.
The MFA-bypass phishing growth trend
The direction is unambiguous across every publisher that measures it. The clearest single accelerant in 2026 is device code phishing, but the broader shift toward MFA-bypass-capable and session-stealing phishing has been building for two years.
Indicator | Change | Window | Source |
|---|---|---|---|
Device code phishing detections | +1,380% | H2 2025 to early 2026 | |
Device code phishing pages | +37.5x | to April 2026 | |
Successful phishing (recaptured datasets) | +400% | 2025 YoY | |
Malicious emails bypassing secure email gateways | +104.5% | 2024 | |
Credential phishing volume | +67% | 2025 YoY | |
Malicious email cadence | 1 every 42s to 1 every 19s | 2024 to 2025 | |
AI-generated phishing instances observed | 413,000+ | 2025 |
Table 2: Session-theft and MFA-bypass phishing growth signals, 2024 to 2026, each attributed to its primary publisher.

A note on interpretation that keeps the trend honest: raw phishing volume is not the same as MFA-bypass capability. Zscaler ThreatLabz actually recorded global phishing volume falling around 20% in 2024 as attackers traded mass spam for high-value, precisely targeted campaigns, and more than 95% of the phishing it saw arrived over encrypted channels. Fewer emails, more of them capable of taking a session. Cofense captures the delivery side of the same shift, with credential phishing accounting for 91% of the active threat reports it published and malicious email cadence more than doubling to one every 19 seconds. The campaigns that land are increasingly built to harvest sessions, not just passwords.
Device code phishing: the fastest-growing MFA bypass of 2026
Device code phishing deserves its own section because it is both the steepest growth curve in the data and the technique that most cleanly defeats the control defenders are being told to adopt. It abuses Microsoft's OAuth 2.0 device authorization grant, the flow designed for signing in on devices without a keyboard. An attacker requests a legitimate device code, then uses a social-engineering lure to get the victim to enter that code on the real Microsoft device-login page and complete a genuine sign-in, MFA and all. While the victim authenticates on the authentic domain, the attacker's script polls the token endpoint and collects the resulting access and refresh tokens.
The consequence is the one that unsettles security teams: because the victim completes a real login on the real identity provider, a passkey works exactly as designed and the attack still succeeds. Push Security is blunt that device code phishing cannot be prevented with authentication controls, including all forms of MFA and even phishing-resistant methods such as passkeys, because the abuse happens on the authorization layer after a successful login. Push measured a 15x rise in device code phishing pages in March 2026 that climbed to 37.5x by early April, and counted more than 14 distinct kits in circulation.
Huntress tracked the same surge from the endpoint side: device code phishing detections up 1,380% between the second half of 2025 and early 2026, and a single wave in March 2026 that hit 344 organizations across the United States, Canada, Australia, New Zealand, and Germany. That campaign abused a legitimate developer platform as token-harvesting infrastructure and used AI to personalize the lures so thoroughly that, across all 344 victims, no two phishing pages were identical, defeating pattern-based detection. The lures themselves often use the ClickFix pattern, instructing the victim to copy a code and paste it into a real Microsoft page, which is why the step feels routine and no lookalike-domain warning fires. Stingrai covers the full chain in its breakdown of device code phishing and ClickFix.
Which MFA methods are phishing-resistant?
Not all MFA is equal against these techniques, and the difference is the single most actionable takeaway in this report. The table below sorts common methods by whether they resist AiTM and phishing-based bypass.
MFA method | Phishing-resistant? | What the statistics say |
|---|---|---|
SMS or voice one-time code | No | Interceptable via SIM swap and SS7 exploitation, and relayed in real time by AiTM kits; CISA recommends moving off it (CISA) |
TOTP authenticator app code | No | Phished in real time through an AiTM proxy that forwards the code to the genuine login (Cisco Talos) |
Push-to-approve notification | No | Defeated by push bombing / MFA fatigue and by AiTM session theft (CISA) |
Number-matching push | Partial | Blunts push fatigue but does not stop AiTM cookie theft; CISA frames it as an interim control, not an endpoint (CISA) |
FIDO2 / WebAuthn passkey | Yes | Bound to the real origin, so it refuses to authenticate on a lookalike relay; blocks over 99% of identity attacks as phishing-resistant MFA (Microsoft) |
Smart card / PIV (PKI) | Yes | Certificate-based and origin-bound; named by CISA alongside FIDO as phishing-resistant (CISA) |
Table 3: Phishing-resistant versus bypassable MFA methods, 2026.
The good news is that adoption of the phishing-resistant tier is finally mainstream. The FIDO Alliance reported on World Passkey Day 2026 that roughly 5 billion passkeys are now in use worldwide, that 75% of people have enabled a passkey on at least one account, and that 68% of organizations have deployed or are deploying passkeys for employees.

Two caveats keep this from being a victory lap. First, enrollment is uneven: Cisco Talos notes from Cisco Duo telemetry that WebAuthn still makes up a very low share of all MFA authentications actually performed, so many accounts that could use a passkey are still falling back to a bypassable factor. Second, as the device code phishing data shows, a passkey only protects the login it is used for. Authorization flows that run after a successful login, and any account that still permits a weaker fallback method, remain reachable. Phishing-resistant MFA is necessary and close to decisive, but only when the weaker paths around it are removed.
What MFA bypass costs: the breach economics
The financial case for closing these gaps is now measured, not assumed. The IBM Cost of a Data Breach Report 2026 puts the global average breach at a record US$4.99 million, up 12% year over year, and finds that phishing remained the single most common initial attack vector for the fourth consecutive year. The most expensive entry points are the human ones: phishing and its voice and SMS variants averaged US$5.29 million per breach, and breaches driven by stolen or compromised credentials take the longest of any vector to identify and contain.
The Verizon Data Breach Investigations Report 2026 adds the structural context. Exploitation of vulnerabilities reached 31% and overtook stolen credentials as the top initial access vector for the first time in the report's history, but that is a story about credentials being displaced at the front door, not disappearing. Credentials still show up as compromised data in a large share of breaches, and the pivot to session and token theft is precisely how attackers keep monetizing identity even as raw credential-stuffing declines. When the password stops being the way in, the session becomes the way in.
What this means for your security program
The statistics converge on one operational conclusion: if your identity defense is measured by whether MFA is enabled, you are measuring the wrong thing. The questions that matter in 2026 are whether your MFA is phishing-resistant, whether weaker fallback methods have been removed, whether your team can detect a replayed session token, and whether an attacker who steals a session can be evicted before the nine-minute mark Obsidian observed.
The most direct way to find out is to test it the way an attacker would. A social engineering assessment and a controlled phishing simulation measure whether AiTM, device code, and consent-phishing lures actually succeed against your users and your identity configuration, rather than assuming your MFA policy holds. A full red team or adversary simulation goes further, chaining an initial session theft into the lateral movement and privilege escalation that follow, so you see the real blast radius rather than a single compromised inbox.
Stingrai is a Toronto and London based, CREST-accredited penetration testing provider founded in 2021, and it runs these engagements as both one-time annual assessments and continuous testing programs, so identity and phishing defenses can be validated on the cadence your risk demands. If you want to pressure-test your MFA against the exact techniques in this report, get a quote. For the companion data on the credentials feeding these attacks, see the Stingrai breached password statistics for 2026.
Frequently Asked Questions
Can MFA be bypassed?
Yes. Multi-factor authentication is regularly bypassed in 2026, and the presence of MFA no longer predicts whether an account survives an attack. Proofpoint found that 59% of the accounts attackers successfully took over in 2025 had MFA enabled, and Obsidian Security found MFA failed to prevent the attack in 84% of its incident responses. The most common bypasses do not defeat the factor directly; they steal the authenticated session token issued after a genuine MFA login, through adversary-in-the-middle phishing, infostealer cookie theft, or device code phishing.
How common are MFA bypass attacks?
Very common against defended targets, and growing fast. Proofpoint reports that 99% of organizations faced account-takeover attempts in 2025 and 67% suffered at least one successful takeover, with MFA enabled on 59% of the compromised accounts. Device code phishing, one specific bypass, rose 37.5x in phishing pages by April 2026 according to Push Security and 1,380% in detections according to Huntress. By raw volume, simple password attacks still dominate the roughly 600 million daily identity attacks Microsoft observes, but MFA-bypass techniques are the ones aimed at the accounts that already have MFA.
What is an adversary-in-the-middle (AiTM) attack?
An adversary-in-the-middle attack puts an attacker-controlled reverse proxy between the victim and the real login page. The victim signs in and completes MFA through the relay, the login genuinely succeeds on the real service, and the attacker copies the session cookie the identity provider issues, then replays it to take over the account. It bypasses MFA because the authentication really happened; the victim performed every factor, so no SMS, app code, or push is ever defeated. AiTM is sold as a service through kits such as Tycoon 2FA, which Proofpoint reports is the highest-volume AiTM phishing threat in its visibility.
Which MFA methods are phishing-resistant?
FIDO2 and WebAuthn passkeys, and smart card or PIV credentials based on public-key infrastructure, are the phishing-resistant methods. They are bound to the real website origin, so they refuse to authenticate on a lookalike relay domain, which is what defeats adversary-in-the-middle phishing. CISA identifies FIDO/WebAuthn as the only widely available phishing-resistant authentication, and Microsoft reports that phishing-resistant MFA blocks over 99% of identity-based attacks. SMS codes, authenticator-app one-time codes, and standard push approvals are not phishing-resistant, because an AiTM proxy can relay them or the delivery channel can be hijacked.
What is session hijacking and token theft?
Session hijacking is the theft and reuse of the authenticated session token, usually a browser cookie, that a service issues after a successful login. Because that token already carries the completed MFA claim, replaying it grants full access with no second prompt. Attackers obtain tokens through adversary-in-the-middle phishing, through infostealer malware that exfiltrates cookies from the browser, and through abused OAuth flows. SpyCloud recaptured 8.6 billion stolen session cookies and session artifacts in 2025, and reports that phishing datasets now routinely bundle tokens and cookies alongside passwords.
What is device code phishing, and can passkeys stop it?
Device code phishing abuses the OAuth 2.0 device authorization grant. The attacker generates a legitimate device code, tricks the victim into entering it on the real identity provider and completing a normal login, and collects the tokens that result. Passkeys do not stop it. Because the victim completes a genuine login on the real domain, a passkey works exactly as designed, and the attack still succeeds on the authorization layer that runs afterward. Push Security measured device code phishing pages rising 37.5x by April 2026, making it the fastest-growing MFA bypass of the year.
How do I detect AiTM and session-token theft?
Watch the session and identity layers rather than failed logins, because these attacks produce a genuinely successful authentication. The highest-signal detections are a known session appearing on a new device or browser fingerprint, sign-ins from hosting-provider or unusual networks, the same token used from two locations at once, and post-login anomalies such as a new MFA method being registered or new inbox rules being created. Continuous access evaluation lets the identity provider re-check and cut a risky session mid-flight rather than trusting a token until it expires. The Stingrai guide to adversary-in-the-middle phishing detection covers these signals in depth.
What is the difference between AiTM and device code phishing?
Both end in a stolen authenticated session, but they differ in where the deception happens. Adversary-in-the-middle phishing relays a fake login page through a reverse proxy and captures the session cookie as it passes, which means the victim sees a lookalike domain that a passkey or an alert user can reject. Device code phishing uses the real identity-provider domain and has the victim complete a genuine login, so there is no lookalike to catch and passkeys pass normally. AiTM defeats most MFA but can be stopped by phishing-resistant MFA; device code phishing defeats even passkeys because it abuses the authorization flow after login.
How can organizations defend against MFA bypass?
Deploy phishing-resistant MFA, specifically FIDO2 passkeys or PKI smart cards, and then remove the weaker fallback methods that let an attacker downgrade the login. Restrict OAuth consent so users cannot grant standing access to unverified apps, and tightly scope or block the device code authorization flow where it is not needed. Add session-layer controls: shorter token lifetimes, token binding, continuous access evaluation, and a rehearsed runbook to revoke all sessions and evict an attacker quickly, since Obsidian observed exfiltration in as little as nine minutes. Validate all of it with social engineering testing and phishing simulations rather than assuming the configuration holds.
Where can I get the latest MFA bypass and AiTM data?
The primary publishers cited throughout this post are the authoritative sources: the Microsoft Digital Defense Report, Mandiant M-Trends, the Verizon Data Breach Investigations Report, the IBM Cost of a Data Breach Report, Proofpoint State of the Phish, the SpyCloud Annual Identity Exposure Report, and research from Cisco Talos, Push Security, Huntress, Cofense, and Zscaler ThreatLabz, plus CISA and FIDO Alliance guidance. The References section below links each one. This page is refreshed as those publishers release new figures.
References
Microsoft. Microsoft Digital Defense Report 2025. October 2025. https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025. Annual identity and threat telemetry, including daily identity attack volume and phishing-resistant MFA effectiveness.
Microsoft. Defending against evolving identity attack techniques. Microsoft Security Blog, May 2025. https://www.microsoft.com/en-us/security/blog/2025/05/29/defending-against-evolving-identity-attack-techniques/. Details the rise of AiTM credential phishing as MFA adoption grows.
Mandiant (Google Cloud). M-Trends 2026. March 2026. https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026/. Frontline incident-response data on initial infection vectors, OAuth token and session-cookie harvesting, and help-desk MFA bypass.
Proofpoint. State of the Phish and account-takeover threat data. 2025 to 2026. https://www.proofpoint.com/us/resources/threat-reports/state-of-phish. Account-takeover attempt and success rates and the share of compromised accounts with MFA enabled.
Proofpoint. Tycoon 2FA: phishing kit being used to bypass MFA. 2025. https://www.proofpoint.com/us/blog/email-and-cloud-threats/tycoon-2fa-phishing-kit-mfa-bypass. Analysis of the highest-volume adversary-in-the-middle phishing-as-a-service kit.
SpyCloud. 2026 Annual Identity Exposure Report. March 2026. https://spycloud.com/newsroom/annual-identity-exposure-report-2026/. Recaptured session cookies, infostealer credential exposure, and phishing growth.
Verizon. 2026 Data Breach Investigations Report. 2026. https://www.verizon.com/business/resources/reports/dbir/. Initial access vector shares and the role of credentials across breaches.
IBM. Cost of a Data Breach Report 2026. July 2026. https://www.ibm.com/reports/data-breach. Average breach cost, phishing as the leading initial attack vector, and per-vector cost.
Cisco Talos. State-of-the-art phishing: MFA bypass. 2026. https://blog.talosintelligence.com/state-of-the-art-phishing-mfa-bypass/. Mechanics of AiTM kits and Cisco Duo telemetry on WebAuthn adoption.
Push Security. Analyzing the rise in device code phishing attacks in 2026. 2026. https://pushsecurity.com/blog/device-code-phishing. Device code phishing page growth and kit proliferation, and why passkeys do not stop it.
Huntress. EvilTokens and AI-powered device code phishing. 2026. https://www.huntress.com/blog/device-code-phishing-ai-mfa-bypass. Device code phishing detection growth and single-wave victim counts.
Cofense. Annual State of Email Security by the numbers. 2025. https://cofense.com/blog/annual-state-of-email-security-by-the-numbers/. Credential phishing volume, secure email gateway bypass, and malicious email cadence.
Zscaler ThreatLabz. 2026 Phishing and Initial Access Report and 2025 Phishing Report. 2025 to 2026. https://www.zscaler.com/blogs/security-research/one-click-compromise-threatlabz-2026-phishing-and-initial-access-report. AiTM and browser-in-the-middle kit trends and AI-generated phishing volume.
CISA. Implementing Phishing-Resistant MFA and More than a Password. https://www.cisa.gov/MFA. Guidance identifying FIDO/WebAuthn as phishing-resistant and naming common MFA-bypass methods.
FIDO Alliance. Accelerating global passkey adoption, World Passkey Day 2026. May 2026. https://fidoalliance.org/fido-alliance-reports-accelerating-global-passkey-adoption-on-world-passkey-day-2026/. Passkey usage and enterprise deployment figures.
Obsidian Security. 2025 SaaS Security Threat Report. January 2025. https://www.obsidiansecurity.com/news/obsidian-security-launches-2025-saas-security-threat-report. MFA failure rate in incident response, SaaS breach growth, and time to exfiltration.



