ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing
|by Alpha Team

ZeroFox Intelligence Brief - Social Engineering Series: MFA Bypass via Phishing
Product Serial: B-2024-03-12a
TLP:CLEAR
ZeroFox's Social Engineering series breaks down aspects of the threat into digestible reports and outlines defensive actions that can be taken to combat it. Part Three of this series takes a deep dive into the bypassing of multi-factor authentication (MFA) security protocols, why and how threat actors do it, and how the threat can best be mitigated.
Standing Intelligence Requirements
Social Engineering, Phishing, MFA Bypass
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- MFA uptake has been on a consistent upward trajectory since its inception, and today its use is widely expected, considered best practice, and a part of basic cybersecurity hygiene.
- Despite improving security, some MFA protocols are still susceptible to bypass or circumvention by threat actors seeking to gain illicit network access. This type of activity is almost certainly on an upward trajectory as of 2024, as threat actors continuously evolve their techniques, tactics, and procedures (TTPs).
Tags: tlp:clear, phishing & fraud