Every Major Breach We've Covered This Year Bypassed MFA Without Stealing a Single Password. Here's What They All Had in Common.

Synthesis Identity Security
July 2026  ·  8 min read

A forgotten credential that opened the door to two hundred companies. A phishing service that captured Microsoft 365 access without ever seeing a password. An autonomous attacker that harvested credentials and moved on within seconds. Three completely different stories with one shared mechanic — and once you see it, the thing your business should be protecting changes. The password was never the prize. The token is.


Think about checking into a hotel. At the desk, they verify who you are — ID, card, the whole routine. It's careful, and it happens once. Then you're handed a key card, and from that moment on nobody asks for your ID again. The card is your identity. Anyone holding it gets into that room, and the door has no opinion about whether they're the person who checked in.

That is almost exactly how logging into a modern business system works. You prove who you are with a password and a multi-factor prompt. In return, the system issues you a token — a small piece of data that says "this person already proved it." From then on, your email, your files, and your apps trust the token, not you. It's how you stay signed in for weeks without re-entering anything.

It's also why the last year of breaches looks the way it does. Attackers stopped trying to beat the front desk. They started stealing key cards.

127%

year-over-year increase in session hijacking — the theft of the access you're already holding

Session and token theft has become one of the fastest-growing attack techniques of 2026 precisely because it sidesteps the two controls most businesses rely on. It doesn't crack your password, and it doesn't defeat your MFA. It waits until after you've successfully passed both, then takes the thing those checks produced. Every defense built around the login is watching a checkpoint the attacker no longer walks through.

The same mechanic, three different stories

We've covered three major incidents in recent weeks that seemed unrelated. They weren't. Set side by side, the pattern is unmistakable:

Three breaches, one shared mechanic

The credential nobody remembered

A login created for a small pilot project in 2022 was never switched off. Four years later attackers used it to get into a vendor's systems — then harvested the connection tokens linking that vendor to its customers, and used those to walk into roughly two hundred customer environments as a trusted partner.

The token was the pivot, not the password

The phishing service that never wanted your password

A federal warning described a subscription phishing kit that captures Microsoft 365 access without ever seeing a password. The victim visits the genuine sign-in page, completes their real MFA correctly — and unknowingly authorizes the attacker's device, which receives a valid token as a result.

MFA completed successfully. Access stolen anyway.

The attack that ran itself

An autonomous agent broke into an exposed server, and the very first thing it did after gaining a foothold was hunt for credentials and access it could reuse to reach the system it actually wanted. When one of its own credentials failed, it rebuilt it in thirty-one seconds and carried on.

Reusable access was the objective from the start

Three unrelated attackers. One shared insight: the password is a formality, and the token is the actual key. Once you hold a valid token, the system treats you as the person who earned it. There is no second check. That is not a flaw someone should patch — it's how the technology is designed to work, and it's why staying logged in is convenient in the first place.

Here's the consequence most businesses haven't absorbed: a stolen token can survive the fix you'd instinctively apply. In many default configurations, the long-lived "refresh" tokens that keep you signed in persist for weeks or months — and can outlive a password reset, and in some cases even survive re-enrolling in MFA. If your response to a suspected compromise is "we changed the password," you may have changed nothing at all from the attacker's point of view. They were never using the password.

How tokens get stolen — four routes, all mundane

None of this requires exotic capability. The four common paths are all things that happen to ordinary businesses on ordinary days.

Malware that empties the browser. Information-stealing malware targets exactly where browsers cache tokens and session cookies. A single infected laptop can hand over active sessions for every service that machine was signed into. Recent research recaptured billions of stolen cookies and session artifacts circulating in criminal markets — those cookies are the tokens.

Phishing that sits in the middle. Attacker-in-the-middle kits relay your login and your MFA code to the real service in real time, then keep the token the service issues. These attacks rose sharply over the past year, with tens of thousands of incidents detected daily. You logged in correctly; someone else kept the receipt.

Consent you granted and forgot. Every "Sign in with…" or "Connect this app" click issues a standing token to a third party. It stays valid until someone revokes it. Most businesses have dozens and have audited none — which is precisely how one compromised vendor became two hundred breached customers.

Devices you authorized without realizing. The device-code technique from the federal warning has the victim complete a genuine, correct login that authorizes someone else's device. Nothing is spoofed. The token is issued legitimately, to the wrong party.

~31% of Microsoft 365 breaches in 2025 involved token theft — now ahead of traditional password-based attacks Session security research 2026
+2,000% spike in third-party app authorization abuse against small business environments — the "connect this app" problem at scale 2026 MSP threat research
8.6bn stolen cookies and session artifacts recaptured from criminal markets in a single year's research 2026 identity exposure research
Notice what these three numbers describe: not passwords, but the things issued after a successful password check. Businesses have spent a decade being told to strengthen passwords and turn on MFA — advice that remains completely correct and that you should absolutely follow. But it protects the front desk. The attacks in this post all happen in the corridor, past the desk, where far fewer people are watching.

What to actually do about it

The reassuring part, as usual, is that the countermeasures are configuration and habit rather than expensive tooling.

1

Learn to revoke sessions, not just reset passwords

Free · Do first

This is the single most important change, because it fixes the response that currently doesn't work. If you suspect an account is compromised, resetting the password may leave the attacker's stolen token perfectly valid. You have to explicitly end the sessions.

Know the path before you need itIn Microsoft 365: admin center → Active users → select the user → sign out of all sessions, and revoke refresh tokens. In Google Workspace: Admin console → Users → select the user → Security → sign the user out of all sessions. Do the password reset and the session revocation, in that order, every time. Write it into your incident response plan.
2

Audit the standing permissions you've handed out

30 minutes · Free

Every connected app holds a token into your environment. Abandoned trials, former tools, and one-off integrations keep theirs indefinitely. This is pure risk with no remaining benefit, and it's the exact path that turned one vendor breach into two hundred.

Do this this weekGoogle Workspace: Admin console → Security → API controls → third-party app access. Microsoft 365: Entra admin center → Enterprise applications. Revoke anything you don't actively use or don't recognize. Then diarise a repeat every quarter.
3

Move your highest-risk accounts to phishing-resistant sign-in

Low cost · High value

Codes and push approvals can be relayed to an attacker in real time. Passkeys and hardware security keys bind the login to a physical device, which defeats the relay entirely. You don't have to do everyone at once — do the accounts that matter most first.

Start hereAdministrators, finance, and anyone who can move money or change payment details. That's usually a handful of people, and it removes the largest share of the risk for the least disruption.
4

Watch for the two things attackers always do next

Free · One conversation

Token theft is quiet — no failed logins, no alerts, nothing for antivirus to catch. But attackers who get in almost always take one of two follow-up actions: they create a mail rule that forwards or hides messages, or they authorize a new third-party app to keep their access alive.

Ask your IT provider today"Do we get alerted when someone creates a new mail-forwarding rule, or when a new third-party app is granted access to our environment — and who actually reads those alerts?" If the answer is no or nobody, that's the gap to close.
To be clear, none of this means MFA was a waste of time. MFA remains one of the highest-value controls any small business can turn on, and the overwhelming majority of attacks are still stopped by it. The point is narrower and more useful: MFA protects the moment of logging in. It does not protect what that login produces. Those are two different jobs, and until recently only one of them was on anybody's list.
The Veriti Spottr CyberScore's Security Posture assessment covers exactly this second job — the session management, third-party access hygiene, and authentication strength that determine whether a stolen token becomes a contained incident or a two-hundred-company cascade. Our Threat Intelligence feed tracks the token-theft campaigns as they emerge. The front desk is well defended in most businesses. The corridor usually isn't.

The short version

For twenty years, security advice has centred on the password: make it long, make it unique, add a second factor. That advice worked well enough that attackers went around it. They now target the thing your successful login creates, because a token is simpler to steal, invisible when used, and frequently survives the very fix you'd apply.

So keep the strong passwords and keep the MFA. But add the second question, the one almost nobody is asking yet: who is currently holding a key to my business — and how would I take it back? If you can't answer that in under five minutes, that's this week's job. It's free, it takes about half an hour, and it closes the door that every significant breach of the past year walked through.

Find out whether the controls that stop token theft are actually in place. Free to start.

View the Threat Intelligence feed → Find Out More About Veriti Spottr →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.