By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “How Hackers are Outsmarting Modern Security Defenses and Why Behavior Context Matters” (January 22, 2026)

TL;DR: Token theft accounted for 31% of MFA bypass attacks in the 2025 Verizon DBIR, while phishing-as-a-service and deepfake voice cloning let low-skilled attackers evade rule-based checks and nearly trigger $240K in fraud, according to Abnormal AI. The real security gap is not authentication alone, but whether programs can distinguish normal from abnormal behavior across identity and SaaS activity.


At a glance

What this is: This is an analysis of why MFA, token-based controls, and rule-based checks fail against modern phishing, session theft, and AI-enabled impersonation.

Why it matters: It matters because identity teams must move from single-event verification to behavioural and contextual detection across human access, NHI tokens, and AI-assisted activity.

By the numbers:

  • 31% of MFA bypass attacks in the 2025 Verizon DBIR relied on token theft, making session hijacking the top MFA evasion technique.
  • Attackers nearly triggered $240K in fraud after a deepfake voice clone bypassed a phone-verification control.

Context

MFA and rule-based controls are designed to validate a login, message, or call at a single point in time. That model breaks when attackers steal session tokens, proxy authentication, or imitate trusted voices and workflows well enough to look normal in the moment.

The identity governance problem is broader than authentication alone. In remote-first SaaS environments, the control boundary now includes tokens, third-party app access, and behavioural context, which means security programmes must decide whether they can recognise abnormal activity after a check has already been passed.


Key questions

Q: How should security teams handle stolen OAuth tokens when MFA is already in place?

A: Treat the incident as post-authentication access, not a login failure. MFA stops the initial sign-in, but it does not control token use after issuance. The response should focus on revocation, rotation, scope review, and behavioural monitoring across the affected SaaS applications because the token itself is the active credential.

Q: Why do phishing-as-a-service attacks remain effective against mature identity controls?

A: They remain effective because they industrialise delivery, infrastructure, and evasion. Mature controls often assume attackers will be noisy or technically limited, but PhaaS lowers the skill threshold and packages credential theft, MFA bypass, and resilient hosting into a repeatable service. That means the defence problem is no longer attacker expertise, but whether the programme can detect abnormal behaviour fast enough.

Q: What are the signs that rule-based controls are failing in SaaS environments?

A: The clearest signs are trusted tools used in unexpected sequences, familiar senders tied to unusual request timing, and successful logins followed by actions the user or service normally would not take. When those signals appear together, the issue is not just a suspicious event but a control model that is too brittle for modern identity activity.

Q: What should organisations do after a deepfake scam is suspected but before the loss is fully understood?

A: Once a deepfake scam is suspected, teams should halt pending transfers, notify banks immediately, preserve chat logs and call recordings, and escalate to fraud, security, and legal responders at once. Rapid containment matters because these scams can involve multiple transactions and delayed discovery. Organisations should also review whether identity verification, approval workflows, and employee awareness controls failed at the same time.


Technical breakdown

Why token theft defeats MFA

MFA protects a login event, but it does not inherently protect the authenticated session that follows. When attackers use adversary-in-the-middle phishing proxies or similar tooling, they relay the user through the real sign-in flow, capture the resulting session cookie or token, and then operate as the legitimate user without re-entering credentials. That is why token theft is so effective: the attacker no longer needs to break authentication repeatedly. The source article ties this directly to 31% of MFA bypass attacks in the 2025 Verizon DBIR, which shows the problem is now less about password guessing and more about session continuity.

Practical implication: Treat session tokens and cookies as first-class credentials, not just the initial login.

How phishing-as-a-service scales identity abuse

Phishing-as-a-service turns credential theft into a low-cost subscription model. Instead of building infrastructure from scratch, attackers rent kits, hosting, and delivery mechanisms that package credential capture, MFA bypass, and landing-page resilience into a ready-made workflow. That matters because the barrier to entry falls sharply: the attacker no longer needs advanced skills to mount a convincing campaign. The article also shows how these services blend into common collaboration platforms and use self-healing infrastructure, which makes blocklist-style defences and simple domain reputation checks unreliable.

Practical implication: Assume phishing capability is commoditised and design controls around behaviour, not attacker sophistication.

Why trusted tools and deepfakes bypass rule-based controls

Rule-based controls struggle when the attacker deliberately uses the tools and communication patterns the business already expects. A remote access tool like ScreenConnect can look like ordinary support activity, and a deepfake voice can satisfy a phone-verification step because the control checks identity at the moment of contact rather than continuity of behaviour. The deeper issue is that a known sender, trusted platform, or familiar voice is no longer enough evidence on its own. Behavioural context across email, identity, and SaaS activity becomes the only durable signal when attackers can mimic surface attributes so effectively.

Practical implication: Correlate message flow, access paths, and post-authentication behaviour before trusting a request.


Threat narrative

Attacker objective: The attacker wants to operate as a legitimate user or trusted counterpart long enough to move money, steal data, or extend access without triggering controls.

  1. Entry occurs through phishing, token theft, or a trusted channel abuse that gives the attacker a foothold without needing to defeat MFA outright.
  2. Credential access happens when the attacker captures a session cookie, OAuth token, or other reusable credential that outlives the original login.
  3. Escalation follows when the attacker uses legitimate tools, trusted SaaS platforms, or delegated access to blend into normal activity and extend reach.
  4. Impact is fraud, data theft, or further compromise carried out under the cover of apparently valid sessions and routine business communication.
  • CitrixBleed exploitation 2023: CitrixBleed leaked NetScaler session cookies, letting attackers skip passwords and MFA at Boeing, ICBC, Xfinity and others.
  • Dropbox Sign breach 2024: A compromised back-end service account gave attackers Dropbox Sign customer data, including API keys, OAuth tokens and MFA information.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Surface-level authentication is no longer a trustworthy security boundary: Once an attacker can capture a session token or proxy the login, MFA has already done only part of the job. The control verified entry, not legitimacy over time. That means identity programmes need to stop treating successful authentication as proof of safe access and start treating session continuity as the real governance problem.

Behavioural baseline is now the decisive control concept: This article shows a named concept we would call identity behaviour drift, where the request itself looks valid but the sequence around it does not. That matters because static rules cannot reliably distinguish a support call, a normal SaaS action, and an attacker replaying trusted activity. Practitioners should read this as a shift from policy enforcement to context validation.

The castle-and-moat assumption has collapsed for SaaS identity: Security strategies built around a trusted internal network were designed for a world where identities, devices, and data stayed inside a perimeter. That assumption fails in remote-first, SaaS-first operations because tokens, third-party apps, and AI-assisted workflows move outside the old trust boundary. The implication is that governance must follow activity, not location.

Low-skill attackers now have enterprise-grade reach: Phishing-as-a-service and deepfake tooling have commoditised attacks that once required expertise. That changes the risk model for human identity programmes and for the non-human credentials that those humans delegate to apps and workflows. The practical conclusion is that resilience now depends on recognising abnormal behaviour early, not on assuming sophistication is required for harm.

Human verification controls are being outpaced by synthetic trust signals: A familiar voice, a known sender, or a routine payment request can all be manufactured. The governance mistake is assuming that one trusted signal is sufficient when the attacker can fake several at once. The field needs controls that evaluate the full interaction chain, not one proof point in isolation.

What this signals

Identity behaviour now matters more than authentication success: Security teams should assume that login completion, a trusted sender, or a verified voice can all be counterfeit or replayed. The practical shift is to detect whether the sequence of actions matches normal work, not whether one check was passed.

Session tokens are the new high-value target: When attackers steal reusable tokens, they inherit the session and often avoid further MFA prompts entirely. That makes token visibility, revocation, and anomaly detection central to any modern identity programme.

AI-assisted impersonation expands the attack surface for human and NHI governance: The same playbook that fools phone verification for a payment change can also be used against delegated access, help desk workflows, and SaaS approvals. Governance needs to account for the trust chain, not just the person at the keyboard.


For practitioners

  • Strengthen session-token governance Treat session cookies, OAuth tokens, and delegated app credentials as high-value credentials with monitoring, revocation, and scope review equal to passwords and MFA factors.
  • Model behaviour across email, identity, and SaaS Correlate login patterns, message threads, and application actions so that a request that looks normal in one channel can still be flagged when the surrounding behaviour is inconsistent.
  • Reduce reliance on single-step phone checks Replace one-off verbal verification with multi-signal confirmation that includes sender history, transaction context, and account behaviour before approving sensitive changes.
  • Hunt for legitimate tool misuse Watch for ScreenConnect, SharePoint, DocuSign, and similar trusted services being used in ways that match attacker tradecraft rather than approved business workflows.

Key takeaways

  • This article shows that MFA can be bypassed when attackers steal reusable session tokens or proxy the login, so authentication success is not the same as secure access.
  • The evidence points to a market shift where phishing-as-a-service, trusted tools, and deepfake voice cloning make rule-based controls easier to evade than to trust.
  • Practitioners need behavioural detection, token governance, and multi-signal verification because modern identity attacks succeed by looking normal at the exact moment controls are checked.

Key terms

  • Session Token Exposure: Session token exposure occurs when authentication tokens or session artifacts are stored, transmitted, or logged in places they should not be. Once exposed, they can function like reusable credentials. This makes them part of identity and access risk, not only application behaviour.
  • Phishing-as-a-service: A criminal service model that packages phishing infrastructure, templates, delivery tools, and sometimes evasion features for reuse by multiple attackers. It lowers the skill threshold for advanced campaigns and makes targeted identity abuse more repeatable across victims and sectors.
  • Behavioral Detection: A monitoring approach that looks for unusual activity rather than relying only on static inventories. For SaaS integrations, it detects drift in token use, data movement, timing, and endpoint behavior so teams can spot compromise, misuse, or automation that no longer matches its expected pattern.
  • Deepfake-based impersonation: A fraud technique that uses synthetic audio, video, or both to make an attacker appear to be a trusted person during a live interaction. The tactic exploits human trust in familiar cues and often aims to trigger urgent actions such as payments, resets, or access changes before verification is challenged.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org