Treatmybrand


a Kainjoo SA Venture
Ch. du Vernay 14a
1196 Gland
+41.21.561.34.96
[email protected]

Support


Monday to Friday
8AM to 8PM
[email protected]
Back

How Attackers Are Bypassing MFA in Financial Services: The Rise of Token Theft and Social Engineering

Recent reports reveal a new wave of attacks targeting financial services that bypass traditional password theft. Instead, attackers use social engineering on IT support lines to reset multi-factor authentication (MFA) and register their devices, gaining persistent access through stolen tokens. The CrowdStrike 2026 Financial Services Threat Landscape Report highlights Mutant Spider as a top adversary, leveraging voice phishing over Microsoft Teams to manipulate employees. The FBI warns of Kali365, a phishing-as-a-service platform exploiting Microsoft OAuth’s device code flow — a legitimate feature that bypasses MFA on the attacker’s side. Additionally, the Verizon 2026 Data Breach Investigations Report notes a shift from credential theft to exploiting vulnerabilities.

These attacks expose weaknesses in current MFA implementations, which often lack out-of-band verification and fail to restrict risky authentication flows. Financial services organizations are urged to implement stricter controls, such as registering FIDO2 hardware keys, restricting OAuth device code flows, monitoring token usage, auditing SaaS activity, and redistributing security budgets to prioritize these emerging threats.

The industry’s focus on preventing password theft overlooks the reality that attackers now exploit legitimate authentication mechanisms and token-based access, which traditional defenses often miss. The evolving threat landscape calls for a strategic reconsideration of how MFA protects access and where organizations invest their security resources.

Venturebeat
Venturebeat