zerofox logo
Advisories

ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing

|by Alpha Team

banner image

ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing

Product Serial: B-2024-03-12a

TLP:CLEAR

ZeroFox's Social Engineering series breaks down aspects of the threat into digestible reports and outlines defensive actions that can be taken to combat it. Part Three of this series takes a deep dive into the bypassing of multi-factor authentication (MFA) security protocols, why and how threat actors do it, and how the threat can best be mitigated.

Standing Intelligence Requirements

Social Engineering, Phishing, MFA Bypass

For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:

https://cloud.zerofox.com/intelligence/advisories/14956

Link to Download

View the full report here

Key Findings

  • MFA uptake has been on a consistent upward trajectory since its inception, and today its use is widely expected, considered best practice, and a part of basic cybersecurity hygiene.
  • Despite improving security, some MFA protocols are still susceptible to bypass or circumvention by threat actors seeking to gain illicit network access. This type of activity is almost certainly on an upward trajectory as of 2024, as threat actors continuously evolve their techniques, tactics, and procedures (TTPs).

Tags: tlp:clear,  phishing & fraud