By NHI Mgmt Group Editorial TeamBased on WorkOS: “How attackers are bypassing MFA using AI in 2026” (April 2, 2026)

TL;DR: AI-powered phishing in 2026 is shifting from password theft to real-time session hijacking, with AiTM proxying, MFA fatigue, fallback abuse, and consent phishing weakening controls that were tuned for automated attacks, according to WorkOS and cited incident data. MFA still matters, but authentication alone no longer closes the gap between login success and session compromise.


At a glance

What this is: WorkOS examines how AI phishing now bypasses MFA by stealing sessions, exploiting fallback paths and abusing OAuth consent instead of attacking passwords alone.

Why it matters: IAM teams need to treat authentication, session control and authorization governance as separate problems, because enabling MFA no longer guarantees that an account is actually protected.


Context

MFA was designed to reduce automated credential attacks, not to stop an attacker who can relay a live login flow and steal the resulting session. That distinction matters for identity governance because the control plane has shifted from the password challenge to the authenticated session and its fallback paths.

In practical terms, AI phishing now targets the parts of access that sit after login success: session cookies, token lifetimes, OAuth consent and recovery methods. The article's central message is that MFA remains necessary, but it no longer describes the full security boundary for human identity programmes.


Key questions

Q: What breaks when MFA is enabled but fallback methods remain active?

A: The strongest factor stops defining the real security boundary. If users can still recover access through SMS, push prompts or password resets, attackers target the easier route and bypass the phishing-resistant method entirely. Organisations should treat every fallback as part of the authentication control, because the weakest reachable path determines practical security.

Q: Why do AiTM phishing kits still succeed against MFA?

A: AiTM kits succeed because they capture the authenticated session, not just the password. If the attacker can intercept the one-time code and the session cookie during login, MFA has already done its job and the cookie becomes the reusable credential. Defenders therefore need controls that watch for session replay and token abuse after sign-in.

Q: What are the signs that authentication controls are being downgraded in practice?

A: Look for high use of recovery flows, repeated push approvals, unexpected QR fallback usage and OAuth grants to unfamiliar applications. Those signals show that users are being steered away from your strongest factor and into weaker, easier-to-abuse paths that undermine the intended protection.

Q: When should organisations prioritise token and session governance over more MFA rollout?

A: Organisations should prioritise token and session governance when they already have MFA coverage but still lack visibility into what happens after authentication. If attackers can reuse active sessions, delegated permissions, or exposed tokens, stronger login controls will not stop post-authentication abuse. The higher-value move is to reduce the lifetime and reach of trusted access.


Technical breakdown

Adversary-in-the-middle attacks steal the session, not just the password

AiTM phishing places a proxy between the user and the real service so the victim completes a genuine login while the attacker relays each step. The crucial output is the session cookie issued by the identity provider or application after successful authentication. Once stolen, that cookie can be replayed without re-entering the password or second factor, which makes the authenticated session the real target. This is why MFA can be working exactly as designed and still fail to protect the account. The control gap is not authentication weakness alone, but the assumption that authentication and session security are the same thing.

Practical implication: treat post-authentication session binding and anomaly detection as core identity controls, not optional hardening.

Fallback authentication creates a downgrade path for phishing resistance

Phishing-resistant methods such as FIDO2 and passkeys depend on the cryptographic binding between the authenticator and the real domain. That protection collapses when organisations keep weaker backup methods active, such as SMS, push approvals, QR fallback or password reset paths. Attackers do not need to defeat the strongest method if they can coerce the login flow into offering a weaker one. In governance terms, the problem is not simply that legacy methods exist, but that they remain reachable in the same authentication journey. A single insecure fallback can invalidate the practical security value of the stronger factor.

Practical implication: map and remove every recovery and fallback path that bypasses your strongest authentication method.

Consent phishing moves the attack below the authentication layer

Consent phishing works by tricking users into granting OAuth permissions to malicious applications through legitimate approval screens. The attacker then receives tokens that operate independently of the login event, which means password changes and MFA re-enrolment do not necessarily remove access. This is an authorization problem, not an authentication problem. It exposes a common governance blind spot: many organisations track who authenticated, but not which third-party apps were authorised, what scopes were granted, or whether consent remains appropriate over time. That makes OAuth governance a parallel control plane, not an extension of MFA.

Practical implication: govern app consent, permission scope and token revocation with the same discipline used for privileged access.


Threat narrative

Attacker objective: The attacker wants durable access to the victim's account and downstream SaaS data without needing to keep the password or second factor.

  1. Entry occurs through AI-generated phishing, voice phishing or a fake login flow that convinces the victim to authenticate against attacker-controlled infrastructure.
  2. Credential access is replaced by real-time relay, where the attacker captures the authenticated session cookie, token or MFA result as it is issued.
  3. Escalation happens when the stolen session is replayed from a separate device or when fallback methods and OAuth consent provide a longer-lived access path.
  4. Impact is unauthorized account access, token persistence and downstream movement into email, SaaS or other connected enterprise systems.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Session security has become the real MFA control point: MFA now protects only the login ceremony, not the access path that follows it. AiTM phishing proves that a successful second-factor challenge can coexist with a compromised session, which means identity programmes that stop at authentication are measuring the wrong boundary. Practitioners need to treat session binding, device signals and token lifetime as first-class governance issues.

Fallback authentication is a governance failure, not a convenience feature: A phishing-resistant factor is only as strong as the weakest recovery path attached to it. SMS codes, push approvals, QR fallbacks and password resets create downgrade routes that attackers can intentionally trigger. The practical lesson is that resilience in human identity depends on removing alternative paths that are easier to exploit than the primary factor.

Consent phishing exposes an authorization gap that MFA cannot cover: OAuth consent is a parallel access grant, not an authentication event. Once a user approves a malicious application, the resulting token can outlive the login session and remain valid until explicitly revoked. That makes token governance and consent review part of identity security, not an adjacent admin task.

Session theft and fallback abuse create identity blast radius, not isolated compromise: One stolen session can unlock email, collaboration tools and downstream resets that amplify the incident beyond the original login. The article shows that the blast radius now depends on how long sessions live and how many recovery paths remain open. Practitioners should re-evaluate where their actual trust boundary begins and ends.

Threat actors are monetizing MFA bypass as a commodity service: The commercialisation of AiTM kits means organisations are no longer defending against bespoke tradecraft alone. The market is rewarding repeatable session theft, fallback abuse and consent manipulation because those techniques work at scale. That should push identity leaders to prioritise continuous session control and authorization governance over checkbox MFA deployment.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

Session theft changes the control model: Once attackers can relay a live login and replay the resulting cookie, the programme boundary moves from authentication to session governance. Continuous access evaluation, device binding and token lifetime reduction become the controls that determine whether a successful login remains trustworthy.

Fallback paths are the weakest link in phishing-resistant identity: Passkeys and FIDO2 help only when organisations remove the recovery and downgrade options that still route users into SMS, push or password-based flows. The practical test is whether a user can still be pushed onto an easier path when the primary factor resists attack.

OAuth consent needs the same scrutiny as privileged access: Third-party app approval is an authorization grant that can outlive a login session and survive password changes. Teams need visibility into who consented, what scope was granted and when tokens should be revoked.


For practitioners

  • Strengthen session-layer controls Bind sessions to device and context signals, shorten token lifetimes, and terminate sessions that change IP, geography or device posture unexpectedly.
  • Remove insecure authentication fallbacks Eliminate SMS, push and password-only recovery paths once phishing-resistant methods are deployed, and audit every downgrade route users can still reach.
  • Implement phishing-resistant authentication for high-risk accounts Deploy passkeys or FIDO2 keys first for administrators, finance teams and access to sensitive systems before extending the rollout to the broader workforce.
  • Govern OAuth consent and token revocation Inventory user-granted applications, restrict high-risk scopes, review consent regularly and revoke tokens when risk conditions or app ownership change.

Key takeaways

  • AI phishing now defeats many MFA deployments by stealing authenticated sessions rather than trying to crack credentials directly.
  • Fallback methods and OAuth consent often determine whether a strong authentication method actually protects the account in practice.
  • Identity teams should focus on session binding, downgrade path removal and token governance if they want MFA to remain effective.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe article centres on phishing-resistant authentication being bypassed through live session relay and fallback abuse.
NHI-07 — Long-Lived SecretsSession cookies and tokens become the attacker target once MFA is defeated in real time.
NHI-10 — Human Use of NHIUsers are being manipulated into granting access through phishing, consent screens and fallback channels.
Recommendation — Harden authentication flows so primary factors cannot be bypassed through relay, downgrade or recovery paths. Shorten token lifetimes and revoke session material aggressively when risk signals change. Separate user-driven approval paths from privileged access decisions and monitor for coercion patterns.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementFallback paths, token handling and authenticator lifecycle are central to the problem described.
Recommendation — Apply authenticator management controls to remove weak recovery methods and govern credential lifecycle.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsOAuth consent and session reuse create authorization risk beyond the initial login event.
Recommendation — Review entitlements and authorizations for third-party apps and revoke unnecessary access promptly.

Key terms

  • Adversary-in-the-middle Attack: An adversary-in-the-middle attack intercepts and relays authentication in real time between the user and the legitimate service. It is especially dangerous for OTPs because the attacker can capture the code while it is still valid and immediately use it to complete login.
  • Session Hijacking: Session hijacking is the takeover of an authenticated session after the original login has completed. The attacker does not need to know the password if they can use the active session token, which is why session monitoring and revocation are essential controls in SaaS identity governance.
  • Fallback authentication: Fallback authentication is the secondary method used when the primary sign-in factor is unavailable. For passkey deployments, fallback must be tightly governed because it often becomes the attacker’s preferred route if it remains easier to abuse than the main login path.
  • OAuth App Consent Phishing: A social engineering technique that tricks users into granting a malicious application access to their accounts or data. The app appears legitimate, but the consent flow is used to gain foothold, collect tokens, or redirect the victim into a credential capture page that can lead to account takeover.

Deepen your knowledge

Identity lifecycle management, secrets management, and workload identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 6, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org