For years, IT professionals treated Multi-Factor Authentication (MFA) as the ultimate shield against credential theft. That false sense of security shattered in 2025. Adversary-in-the-Middle (AiTM) attacks began bypassing traditional MFA at an unprecedented scale, catching many organizations completely off guard. Now, in 2026, this trend has aggressively accelerated, becoming the primary engine driving Business Email Compromise (BEC).

Relying on legacy MFA protocols leaves your clients exposed to sophisticated threat actors. You need to understand how these attacks function and adapt your security posture immediately to prevent catastrophic data breaches.

In this article, you will learn:

  • The exact mechanics of how AiTM attacks bypass standard MFA
  • Why the 2026 BEC threat landscape demands a proactive security shift
  • Actionable best practices to secure your clients' vulnerable environments
  • How s90 delivers a security-forward approach to neutralize these modern threats

The Mechanics of AiTM Phishing

To stop AiTM phishing, you must first understand how threat actors manipulate the authentication process.

Stealing the Session Token

Traditional phishing steals usernames and passwords. AiTM phishing goes a step further by stealing the authentication session itself. Attackers deploy a proxy server that sits directly between the user and the legitimate login portal. When your client clicks a malicious link, they see a perfect replica of their usual Microsoft 365 or Google Workspace login screen.

Here's how the attack unfolds:

  1. The user enters their credentials into the fake page, which the proxy forwards to the real site in real-time
  2. The legitimate site prompts for an MFA code, which the user receives and enters
  3. The proxy forwards the MFA code to the real site, completing authentication
  4. The real site generates a session cookie — which the attacker intercepts
  5. The attacker now bypasses the login process entirely on their own machine

This process requires no malware and easily defeats SMS texts, voice calls, and standard authenticator app prompts.

The 2025 Tipping Point — and 2026 Acceleration

The threat landscape shifted permanently over the last 18 months, rendering basic compliance checkboxes obsolete.

MFA Bypass at Scale

In 2025, cybercrime syndicates commercialized AiTM infrastructure. Highly automated phishing kits were packaged and sold as a service on the dark web, lowering the barrier to entry and allowing low-skilled attackers to execute sophisticated MFA bypass campaigns. The result: a dramatic spike in successful breaches across every industry.

Fueling the BEC Threat Landscape

This surge in compromised accounts directly fuels the modern BEC crisis. Once an attacker steals a session token, they gain full access to the victim's email inbox — quietly monitoring communications, studying payment workflows, and identifying key vendors. In 2026, these actors leverage AI tools to draft flawless, highly convincing emails instructing finance teams to reroute wire transfers. Because the emails originate from a legitimate, authenticated account, standard email security filters miss them entirely.

Traditional MFA provides zero protection once the attacker holds the session token.

Common Mistakes IT Teams Make with MFA

Understanding where defenses fail is the first step toward building a resilient security architecture.

Relying Solely on Push Notifications

Many IT teams upgraded clients to push-notification MFA, assuming it offered superior protection. Attackers counter this with "MFA fatigue" — flooding the user's phone with approval requests until a frustrated user approves one just to make it stop. AiTM proxies also capture the session tokens generated after a push approval, making this method highly vulnerable regardless.

Ignoring Session Token Security

IT providers often focus entirely on securing the initial login event, monitoring failed login attempts while ignoring the lifecycle of the session token. If a token remains valid indefinitely — or if conditional access policies don't restrict where a token can be used — attackers have a massive window to exploit a compromised account.

Focusing only on the password ignores the actual key to the kingdom.

Best Practices to Secure Clients Against AiTM

You must implement proactive, layered defenses to protect your clients from session hijacking.

Transition to Phishing-Resistant MFA

The most effective defense against AiTM attacks is migrating to FIDO2 (Fast Identity Online) standard authentication. Security keys such as YubiKeys or Windows Hello for Business bind the authentication request to the specific device and domain. If a user lands on a proxy site, the FIDO2 protocol recognizes the domain mismatch and immediately halts the authentication process — neutralizing the AiTM proxy entirely.

Implement Strict Conditional Access

Deploy robust conditional access policies to limit how and where session tokens function:

  • Restrict logins to known, managed devices
  • Enforce location-based policies that block access from unexpected countries or IP ranges
  • Enable continuous access evaluation to force immediate re-authentication when a critical security event is detected — such as a sudden change in network location

Layering these controls dramatically reduces the usefulness of a stolen session token.

How s90 Delivers Security-Forward Protection

Your clients rely on you to stay ahead of the curve, and s90 provides the infrastructure to make that happen.

We understand that protecting clients in 2026 requires more than reactive alerting. s90 operates as a security-forward solution provider, building our architecture specifically to neutralize advanced threats like AiTM and BEC. Our platform integrates phishing-resistant authentication frameworks, dynamic conditional access, and continuous session monitoring by default — actively severing the attack chains that cybercriminals rely on.

With s90, you transition your clients from vulnerable legacy setups to resilient, modern security postures that keep their operations secure and uninterrupted.

Conclusion

The rapid escalation of AiTM attacks proves that legacy MFA can no longer protect your clients. Attackers bypass traditional authentication daily, using stolen session tokens to launch devastating BEC campaigns. To survive the 2026 threat landscape, moving beyond basic passwords and SMS codes isn't optional — it's essential.

Implementing FIDO2 authentication, enforcing strict conditional access, and partnering with a security-focused provider are non-negotiable steps for modern IT defense.

Frequently Asked Questions

What is an Adversary-in-the-Middle (AiTM) attack?

Why doesn't traditional MFA stop AiTM attacks?

What is FIDO2 and why is it phishing-resistant?

How does AiTM fuel Business Email Compromise (BEC)?