Why modern phishing attacks increasingly target sessions, trust, and user behaviour
Multi-factor authentication (MFA) has become one of the most widely adopted security controls across modern organisations. It adds an important layer of protection beyond passwords and has significantly reduced the effectiveness of many traditional credential-based attacks.
However, attackers have also adapted.
Rather than attempting to “break” MFA directly, many modern phishing and identity attacks now focus on bypassing authentication workflows entirely by targeting authenticated sessions, browser tokens, trusted applications, and user behaviour.
This shift has contributed to the rise of techniques such as MFA fatigue attacks, adversary-in-the-middle (AiTM) phishing, session hijacking, and consent phishing – all designed to exploit legitimate authentication processes rather than traditional software vulnerabilities.
MFA fatigue attacks
Modern MFA systems commonly rely on push notifications sent to a user’s trusted device. While designed for convenience, attackers increasingly abuse this workflow through what is commonly referred to as MFA fatigue or prompt bombing attacks.
In these attacks, threat actors repeatedly trigger MFA requests after obtaining valid credentials through phishing, password reuse, infostealer malware, or leaked credential databases.
The goal is simple: overwhelm the user until they eventually approve the request out of frustration, confusion, or habit.
Unlike traditional intrusion techniques, MFA fatigue attacks rely heavily on social engineering and user behaviour rather than technical exploitation. In some cases, attackers may even contact victims directly while the prompts are occurring, impersonating internal IT support teams or vendors to encourage approval.
High-profile incidents have demonstrated how effective MFA fatigue attacks can be against organisations relying heavily on push-based authentication workflows.
One widely referenced example was the 2022 Uber breach associated with the Lapsus$ group. After obtaining valid employee credentials from the dark web, the attacker repeatedly triggered MFA push notifications against the employee’s account while impersonating Uber IT support through WhatsApp messages.
Eventually, the employee approved one of the requests to stop the flood of notifications, granting the attacker initial access to Uber’s internal environment.
From there, the attacker was reportedly able to access internal systems, privileged access management tools, VPN services, cloud environments, and internal Slack accounts. The incident highlighted how modern identity attacks increasingly exploit user trust and authentication workflows rather than traditional software vulnerabilities alone.
Adversary-in-the-middle (AiTM) phishing
AiTM phishing has rapidly emerged as one of the most concerning phishing techniques targeting modern authentication systems.
Unlike traditional phishing pages that simply steal usernames and passwords, AiTM phishing kits act as a live proxy between the victim and the legitimate login service.
When the victim enters their credentials and MFA code into the phishing page, the attacker intercepts the authenticated session in real time before forwarding the request to the legitimate service.
To the victim, the login experience can appear completely normal.
This allows attackers to bypass MFA protections without needing to directly compromise the authentication mechanism itself. Instead, they steal the authenticated session created after MFA has already been successfully completed.
Modern phishing-as-a-service kits increasingly support AiTM functionality, significantly lowering the barrier for attackers to conduct sophisticated identity attacks at scale.
Session hijacking and token theft
Once users successfully authenticate, websites and cloud services typically create temporary authenticated sessions using cookies or browser session tokens.
Attackers increasingly target these sessions directly.
If a valid session token is stolen, attackers may be able to impersonate the legitimate user without needing to re-enter credentials or trigger MFA again.
Session hijacking and token theft can occur through:
- phishing kits
- AiTM attacks
- infostealer malware
- malicious browser scripts
- unsecured sessions
- intercepted traffic
Modern phishing campaigns increasingly focus on stealing authenticated browser sessions rather than passwords alone because authenticated sessions often provide immediate access to corporate systems, cloud platforms, and SaaS environments.
This shift reflects a broader trend across identity-focused attacks: targeting trusted authenticated states instead of attempting to repeatedly defeat login protections.
Consent phishing
Some modern attacks do not attempt to steal credentials or MFA codes at all.
Instead, attackers abuse legitimate OAuth and cloud application permission workflows to trick users into granting access directly.
This technique, commonly referred to as consent phishing, typically involves malicious third-party applications impersonating legitimate Microsoft 365 or Google Workspace integrations.
Victims may receive realistic permission prompts requesting access to:
- email accounts
- cloud files
- calendars
- contacts
- mailbox permissions
- the ability to send emails on the user’s behalf
If approved, attackers can gain persistent access to the account without ever needing the user’s password or MFA token.
Because the access appears legitimately authorised by the user, these attacks can be particularly difficult for traditional security tooling to detect.
Consent phishing continues to grow in popularity because it exploits normal workplace behaviour and trusted cloud application workflows that users interact with daily.
MFA still matters
Despite the rise of these attack techniques, MFA remains one of the most effective security controls organisations can implement.
However, modern identity attacks demonstrate that authentication security can no longer rely solely on passwords and MFA prompts alone.
Attackers increasingly target:
- authenticated sessions
- trusted devices
- browser tokens
- OAuth permissions
- user behaviour
- legitimate authentication workflows
As phishing and identity-based threats continue to evolve, organisations require greater visibility beyond the login screen itself.
This includes stronger monitoring of suspicious login activity, phishing infrastructure, malicious domains, impersonation campaigns, session abuse, and broader identity threat activity across digital channels.
This is something we continue to see across the work being done at unphish, particularly as phishing infrastructure becomes more sophisticated, scalable, and increasingly focused on bypassing traditional authentication controls rather than attacking them directly.