How attackers bypass MFA in financial services

TL;DR AI
2 min readKey summary
Attackers are bypassing MFA at financial firms by posing as IT support, pressuring help desks to reset accounts, and using voice phishing.
They are also abusing device-code authentication to steal OAuth tokens, enabling access to Microsoft 365 and Teams environments.
CrowdStrike, the FBI, and Verizon say password theft is declining as an initial access method, while exploitation and token abuse are rising.
The trend shows MFA alone is no longer sufficient, as attackers can gain persistent access through resets, grants, and vulnerabilities.

