OpusBUSINESS EXPERT

You had multi-factor authentication on. They got in anyway

Andy Shepherd6 min read

Turn multi-factor authentication on and you will be fine. Plenty of people said that, this practice included, and at the time it was the right advice. Microsoft still reckons MFA stops more than 99% of password-based attacks, and nothing below is an argument for turning it off.

But the attack built specifically to get past it wants neither your password nor your six-digit code. It wants the session your successful login produces. A session that MFA has already approved is indistinguishable from you, because for one moment it genuinely was you.

The code is real. That is the point of it

A link arrives and takes you to a Microsoft sign-in page. Not a copy of one. What you are looking at is a relay: it passes whatever you type straight through to the real Microsoft, live, and shows you whatever the real Microsoft sends back.

So you enter your password and Microsoft asks for your second factor, because from Microsoft's side a real sign-in is under way. Your phone buzzes. The prompt comes from the right app, at the moment you were expecting it, naming the service you were trying to reach. You approve it. Microsoft, satisfied, issues the sign-in token, and the relay in the middle keeps it.

Nothing on your side of the screen misbehaves. Usually the page then shows a plausible error and drops you on the real website, where you sign in again, successfully, and forget the whole thing by lunchtime.

Microsoft's name for this is adversary-in-the-middle. What makes it worth writing about is that every check most people have been taught to run has already passed by then. The sender looked right. The code was genuine. The only thing that was wrong was the address in the bar at the top, which is the one thing nobody reads on a phone.

Then it goes quiet

Nobody kicks the door in. The first fortnight is reading: who pays whom, in what tone, on what terms, and which invoice is worth waiting for.

At some point an inbox rule appears. It moves anything mentioning invoices or bank details into a folder nobody opens, so that when the criminal writes to your customer in your name, the customer's reply never reaches you. We have written about the email at the other end of that, the one asking a business to update a supplier's bank details. This is where it is sent from.

The numbers are less dramatic than the story

Government's Cyber Security Breaches Survey for 2025/2026 puts phishing at 38% of UK businesses over twelve months, and it was named the most disruptive incident by 69% of those breached. Half of the businesses that reported a breach reported phishing and nothing else.

The cost figures cut the other way. The median perceived cost of the most disruptive breach was £0, and for micro and small businesses the top 5% of cases reached about £4,000.

38%
of UK businesses hit by phishing in the last year
£0
Median cost of the most disruptive breach or attack

Read those together and you have the actual problem. Nearly all phishing costs a small firm nothing, which is why nearly all small firms treat it as background weather. The rare one that lands on the mailbox that sends invoices is a different event entirely, and it does not announce itself as one.

More training will not fix this

This is the part IT companies dislike saying, because awareness training is easy to sell by the seat.

Against a lookalike domain and bad grammar, training works. Against a relay, there is nothing to spot. The page is Microsoft's own page, redrawn. The prompt is Microsoft's own prompt. Asking a bookkeeper to catch this on a Thursday afternoon by being alert is asking them to read a URL more carefully than the browser does, every time, for years. Some of them will. Not all of them, not always, and once is enough.

Train people by all means. Do not buy it as the control.

What actually stops it

Passkeys. A passkey is bound to the address it was created for, so it simply will not work on a relay pretending to be that address. There is no code to read out, nothing to forward, nothing to approve by mistake. The check happens between the device and the site, and the user's part is a fingerprint or a face.

You do not need to roll them out everywhere at once, and for most firms the attempt would stall. Start where a stolen session is worth money:

  1. 01Whoever sends and chases invoices
  2. 02Whoever holds global admin on your Microsoft 365 tenant
  3. 03The director whose name on an email makes people act
  4. 04Then everyone else, at whatever pace the phones allow

Short of that, three things are worth doing this month, and if you are on Microsoft 365 Business Premium you already own the licensing for all of them. Restrict sign-ins with Conditional Access, so a token is only useful from a device or a place you recognise. Alert on new inbox rules and on any mail forwarding to an outside address, because that rule is the tell and it is visible the day it is created. And find out now, before you need it, who in your business can revoke a signed-in session, because changing a password is not the same as evicting someone. Whoever does that clean-up also has to check what got registered while the intruder was inside; a second authenticator quietly added to the account is how they walk back in after the password change.

None of this is exotic and none of it needs new software. On the estates we run it is a periodic review rather than an emergency, which is the whole difference between finding an inbox rule the week it appears and reading about it in a loss adjuster's report.

If you are not sure whether anyone has ever looked at yours, that is a short conversation and a cheaper one than the alternative.


We work with businesses across Knutsford, Alderley Edge, Wilmslow, Altrincham, Stockport and Warrington, and remotely for clients anywhere in the UK.

If any of this sounds like your business, we will tell you plainly whether we can help.

We would like to use analytics cookies to understand how this site is used, advertising cookies to measure our ads, and to load our office map from Google. None of them loads on its own unless you accept — though Google Tag Manager itself loads either way, with every category switched off. The map also has a button of its own. Read our cookie policy