Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Real-Time MFA Relay
Threats, Abuse & Incident Response

Real-Time MFA Relay

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Threats, Abuse & Incident Response

A live attack pattern where an attacker intercepts a user’s authentication response and reuses it immediately against the legitimate service. The factor is not stolen for later use, but relayed during the same interaction, which defeats controls that assume a delay between approval and attacker action.

What Real-Time MFA Relay Means in Practice

Real-time MFA relay is a live interception pattern, not a delayed credential theft event. The attacker captures the victim’s approval, one-time code, or signed authentication response and forwards it immediately to the target service before the interaction expires.

This matters because many sign-in defenses are designed around the assumption that the user and the service are still in the same trusted exchange. A relay breaks that assumption by preserving timing and continuity, which makes the attacker look like the legitimate user at the moment of authentication.

How the Relay Attack Works

Relay attacks usually sit in the middle of a normal login flow. The attacker first persuades or tricking the user into starting authentication against a fake or attacker-controlled prompt, then forwards the response to the real service in near real time.

The technique is especially effective against mechanisms that are strong against password reuse but weak against live interception. Phishing-resistant methods raise the bar, but any workflow that accepts a human approval without binding that approval to the true origin, session, or transaction context can still be exposed.

In practice, the risk is not just code theft. The attacker may capture a session, a token, or a successful step-up event that can be reused long enough to gain access, move laterally, or change account settings.

Where Real-Time MFA Relay Fits in the Authentication Landscape

Real-time relay sits between simple phishing and full session hijacking. It is related to adversary-in-the-middle activity, but the defining feature is immediate forwarding of the authentication response rather than later reuse of a stored secret.

The strongest defensive distinction is whether the factor is phishing-resistant authentication. Methods that cryptographically bind the authenticator to the origin and session, such as passkeys and FIDO-based flows, are harder to relay than OTPs, push approvals, or browser-based challenge responses.

That is why real-time relay should be understood as an authentication integrity problem, not only an MFA problem. The attacker is exploiting trust in the live verification path, not merely guessing or stealing a password.

Why This Pattern Matters for Security Programs

Real-time relay is most dangerous in environments where authentication is the gateway to high-value systems, administrative consoles, or remote access. Once the attacker crosses that gateway, the follow-on impact is often governed by the privileges behind the account, not by the original login method itself.

It also exposes a common design weakness: assuming that "MFA enabled" automatically means "phishing-safe." A strong second factor still fails if the user can be induced to approve a real-time prompt that the attacker can replay within the same session window.

For that reason, security teams should treat relay-resistant sign-in as a control objective in its own right, especially where remote access, privileged workflows, help desk recovery, or step-up authentication protect sensitive actions.

Risk and Threat Considerations

Real-time MFA relay creates a direct account takeover path because the attacker does not need to defeat the factor offline, only reuse it fast enough to satisfy the target service. That makes it attractive for phishing campaigns, help desk impersonation, and access to environments where one valid sign-in is enough to unlock deeper privileges.

Failure mechanism: The authentication factor is accepted without sufficiently binding it to the real service origin, the intended transaction, or the correct session, so the attacker can relay the response before it expires.

Impact: Successful relay can lead to account takeover, session theft, privilege abuse, lateral movement, and unauthorized changes to authentication or recovery settings.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63Digital Identity GuidelinesDefines authenticator assurance and phishing-resistant authentication for relay-resistant sign-in
Recommendation — Use phishing-resistant authenticators for high-value access and verify the authenticator binds to the real origin.
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Covers organizational user authentication that real-time relay can bypass if factors are relayable
IA-5 — Authenticator ManagementAddresses authenticator lifecycle and secure handling of credentials and one-time secrets
IA-9 — Service Identification and AuthenticationApplies when machine or service sign-in paths are exposed to live relay or token reuse
Recommendation — Require stronger authentication methods for workforce sign-in and step-up access. Manage authenticators so relayable secrets are minimized, rotated, and protected. Bind service authentication to trusted origins and limit reuse of intercepted assertions.
CIS Controls v8CIS-6 — Access Control ManagementSupports controlling access paths that real-time relay can exploit through weak MFA workflows
Recommendation — Restrict access to sensitive systems with stronger sign-in requirements and reduced exposure.

Practitioner Guidance

Why practitioners should care: Real-time relay is one of the clearest examples of why MFA strength and MFA usability are not the same thing. A program can have "multi-factor" coverage and still remain vulnerable if its strongest factors are relayable in real time.

What to watch for: Repeated login prompts, unusual geographic or device transitions during authentication, and user reports of unexpected approval requests often indicate relay or adversary-in-the-middle activity rather than ordinary password abuse.

Practitioner takeaway: Treat phishing-resistant, origin-bound authentication as the default for high-value access paths, and do not rely on approval-only factors where live interception is a realistic threat.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org