TL;DR: AI-powered phishing in 2026 is shifting from password theft to real-time session hijacking, with AiTM proxying, MFA fatigue, fallback abuse, and consent phishing weakening controls that were tuned for automated attacks, according to WorkOS and cited incident data. MFA still matters, but authentication alone no longer closes the gap between login success and session compromise.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “How attackers are bypassing MFA using AI in 2026”.
Key questions
Q: What breaks when MFA is enabled but fallback methods remain active?
A: The strongest factor stops defining the real security boundary.
Q: Why do AiTM phishing kits still succeed against MFA?
A: AiTM kits succeed because they capture the authenticated session, not just the password.
Q: What are the signs that authentication controls are being downgraded in practice?
A: Look for high use of recovery flows, repeated push approvals, unexpected QR fallback usage and OAuth grants to unfamiliar applications.
Practitioner guidance
- Strengthen session-layer controls Bind sessions to device and context signals, shorten token lifetimes, and terminate sessions that change IP, geography or device posture unexpectedly.
- Remove insecure authentication fallbacks Eliminate SMS, push and password-only recovery paths once phishing-resistant methods are deployed, and audit every downgrade route users can still reach.
- Implement phishing-resistant authentication for high-risk accounts Deploy passkeys or FIDO2 keys first for administrators, finance teams and access to sensitive systems before extending the rollout to the broader workforce.
Bottom line: AI phishing now defeats many MFA deployments by stealing authenticated sessions rather than trying to crack credentials directly.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Session security has become the real MFA control point: MFA now protects only the login ceremony, not the access path that follows it. AiTM phishing proves that a successful second-factor challenge can coexist with a compromised session, which means identity programmes that stop at authentication are measuring the wrong boundary. Practitioners need to treat session binding, device signals and token lifetime as first-class governance issues.
A few things that frame the scale:
- Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.
A question worth separating out:
Q: When should organisations prioritise token and session governance over more MFA rollout?
A: Organisations should prioritise token and session governance when they already have MFA coverage but still lack visibility into what happens after authentication. If attackers can reuse active sessions, delegated permissions, or exposed tokens, stronger login controls will not stop post-authentication abuse. The higher-value move is to reduce the lifetime and reach of trusted access.
👉 Read our full editorial: AI phishing is bypassing MFA through session theft and fallback abuse