Every Major Breach We've Covered This Year Bypassed MFA Without Stealing a Single Password. Here's What They All Had in Common.
A forgotten credential that opened the door to two hundred companies. A phishing service that captured Microsoft 365 access without ever seeing a password. An autonomous attacker that harvested credentials and moved on within seconds. Three completely different stories with one shared mechanic — and once you see it, the thing your business should be protecting changes. The password was never the prize. The token is.
Think about checking into a hotel. At the desk, they verify who you are — ID, card, the whole routine. It's careful, and it happens once. Then you're handed a key card, and from that moment on nobody asks for your ID again. The card is your identity. Anyone holding it gets into that room, and the door has no opinion about whether they're the person who checked in.
That is almost exactly how logging into a modern business system works. You prove who you are with a password and a multi-factor prompt. In return, the system issues you a token — a small piece of data that says "this person already proved it." From then on, your email, your files, and your apps trust the token, not you. It's how you stay signed in for weeks without re-entering anything.
It's also why the last year of breaches looks the way it does. Attackers stopped trying to beat the front desk. They started stealing key cards.
year-over-year increase in session hijacking — the theft of the access you're already holding
Session and token theft has become one of the fastest-growing attack techniques of 2026 precisely because it sidesteps the two controls most businesses rely on. It doesn't crack your password, and it doesn't defeat your MFA. It waits until after you've successfully passed both, then takes the thing those checks produced. Every defense built around the login is watching a checkpoint the attacker no longer walks through.
The same mechanic, three different stories
We've covered three major incidents in recent weeks that seemed unrelated. They weren't. Set side by side, the pattern is unmistakable:
The credential nobody remembered
A login created for a small pilot project in 2022 was never switched off. Four years later attackers used it to get into a vendor's systems — then harvested the connection tokens linking that vendor to its customers, and used those to walk into roughly two hundred customer environments as a trusted partner.
The token was the pivot, not the passwordThe phishing service that never wanted your password
A federal warning described a subscription phishing kit that captures Microsoft 365 access without ever seeing a password. The victim visits the genuine sign-in page, completes their real MFA correctly — and unknowingly authorizes the attacker's device, which receives a valid token as a result.
MFA completed successfully. Access stolen anyway.The attack that ran itself
An autonomous agent broke into an exposed server, and the very first thing it did after gaining a foothold was hunt for credentials and access it could reuse to reach the system it actually wanted. When one of its own credentials failed, it rebuilt it in thirty-one seconds and carried on.
Reusable access was the objective from the startThree unrelated attackers. One shared insight: the password is a formality, and the token is the actual key. Once you hold a valid token, the system treats you as the person who earned it. There is no second check. That is not a flaw someone should patch — it's how the technology is designed to work, and it's why staying logged in is convenient in the first place.
How tokens get stolen — four routes, all mundane
None of this requires exotic capability. The four common paths are all things that happen to ordinary businesses on ordinary days.
Malware that empties the browser. Information-stealing malware targets exactly where browsers cache tokens and session cookies. A single infected laptop can hand over active sessions for every service that machine was signed into. Recent research recaptured billions of stolen cookies and session artifacts circulating in criminal markets — those cookies are the tokens.
Phishing that sits in the middle. Attacker-in-the-middle kits relay your login and your MFA code to the real service in real time, then keep the token the service issues. These attacks rose sharply over the past year, with tens of thousands of incidents detected daily. You logged in correctly; someone else kept the receipt.
Consent you granted and forgot. Every "Sign in with…" or "Connect this app" click issues a standing token to a third party. It stays valid until someone revokes it. Most businesses have dozens and have audited none — which is precisely how one compromised vendor became two hundred breached customers.
Devices you authorized without realizing. The device-code technique from the federal warning has the victim complete a genuine, correct login that authorizes someone else's device. Nothing is spoofed. The token is issued legitimately, to the wrong party.
What to actually do about it
The reassuring part, as usual, is that the countermeasures are configuration and habit rather than expensive tooling.
Learn to revoke sessions, not just reset passwords
Free · Do firstThis is the single most important change, because it fixes the response that currently doesn't work. If you suspect an account is compromised, resetting the password may leave the attacker's stolen token perfectly valid. You have to explicitly end the sessions.
Audit the standing permissions you've handed out
30 minutes · FreeEvery connected app holds a token into your environment. Abandoned trials, former tools, and one-off integrations keep theirs indefinitely. This is pure risk with no remaining benefit, and it's the exact path that turned one vendor breach into two hundred.
Move your highest-risk accounts to phishing-resistant sign-in
Low cost · High valueCodes and push approvals can be relayed to an attacker in real time. Passkeys and hardware security keys bind the login to a physical device, which defeats the relay entirely. You don't have to do everyone at once — do the accounts that matter most first.
Watch for the two things attackers always do next
Free · One conversationToken theft is quiet — no failed logins, no alerts, nothing for antivirus to catch. But attackers who get in almost always take one of two follow-up actions: they create a mail rule that forwards or hides messages, or they authorize a new third-party app to keep their access alive.
The short version
For twenty years, security advice has centred on the password: make it long, make it unique, add a second factor. That advice worked well enough that attackers went around it. They now target the thing your successful login creates, because a token is simpler to steal, invisible when used, and frequently survives the very fix you'd apply.
So keep the strong passwords and keep the MFA. But add the second question, the one almost nobody is asking yet: who is currently holding a key to my business — and how would I take it back? If you can't answer that in under five minutes, that's this week's job. It's free, it takes about half an hour, and it closes the door that every significant breach of the past year walked through.
Find out whether the controls that stop token theft are actually in place. Free to start.
View the Threat Intelligence feed → Find Out More About Veriti Spottr →📚 Credential Security Series — Read the full series

Comments
Post a Comment