TL;DR: Token theft accounted for 31% of MFA bypass attacks in the 2025 Verizon DBIR, while phishing-as-a-service and deepfake voice cloning let low-skilled attackers evade rule-based checks and nearly trigger $240K in fraud, according to Abnormal AI. The real security gap is not authentication alone, but whether programs can distinguish normal from abnormal behavior across identity and SaaS activity.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “How Hackers are Outsmarting Modern Security Defenses and Why Behavior Context Matters”.
By the numbers:
- 31% of MFA bypass attacks in the 2025 Verizon DBIR relied on token theft, making session hijacking the top MFA evasion technique.
- Attackers nearly triggered $240K in fraud after a deepfake voice clone bypassed a phone-verification control.
Key questions
Q: How should security teams handle stolen OAuth tokens when MFA is already in place?
A: Treat the incident as post-authentication access, not a login failure.
Q: Why do phishing-as-a-service attacks remain effective against mature identity controls?
A: They remain effective because they industrialise delivery, infrastructure, and evasion.
Q: What are the signs that rule-based controls are failing in SaaS environments?
A: The clearest signs are trusted tools used in unexpected sequences, familiar senders tied to unusual request timing, and successful logins followed by actions the user or service normally would not take.
Practitioner guidance
- Strengthen session-token governance Treat session cookies, OAuth tokens, and delegated app credentials as high-value credentials with monitoring, revocation, and scope review equal to passwords and MFA factors.
- Model behaviour across email, identity, and SaaS Correlate login patterns, message threads, and application actions so that a request that looks normal in one channel can still be flagged when the surrounding behaviour is inconsistent.
- Reduce reliance on single-step phone checks Replace one-off verbal verification with multi-signal confirmation that includes sender history, transaction context, and account behaviour before approving sensitive changes.
Bottom line: This article shows that MFA can be bypassed when attackers steal reusable session tokens or proxy the login, so authentication success is not the same as secure access.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Surface-level authentication is no longer a trustworthy security boundary: Once an attacker can capture a session token or proxy the login, MFA has already done only part of the job. The control verified entry, not legitimacy over time. That means identity programmes need to stop treating successful authentication as proof of safe access and start treating session continuity as the real governance problem.
A question worth separating out:
A: Once a deepfake scam is suspected, teams should halt pending transfers, notify banks immediately, preserve chat logs and call recordings, and escalate to fraud, security, and legal responders at once. Rapid containment matters because these scams can involve multiple transactions and delayed discovery. Organisations should also review whether identity verification, approval workflows, and employee awareness controls failed at the same time.
👉 Read our full editorial: Behavioral AI exposes where MFA and rule-based controls fail