Token Blog: Phishing and Ransomware Articles

Can MFA be Bypassed?

Written by Kevin Surace | Aug 20, 2026, 12:45:00 PM

Multi-factor authentication (MFA) was designed to protect organizations when passwords were stolen. Unfortunately, attackers have adapted to the methods most enterprises now use. They intercept codes, overwhelm employees with approval requests, relay authentication through convincing phishing sites, steal active sessions, manipulate help desks, and exploit account recovery processes. The problem is not the concept of using multiple factors. The problem is that most MFA systems still depend on information or actions that can be shared, intercepted, relayed, reset, or approved by the wrong person.

SentinelOne recently outlined several of the most common MFA bypass techniques, including prompt bombing, session theft, SIM swapping, adversary in the middle phishing, help desk social engineering, real time phishing tools, and OAuth consent attacks. Together, these techniques demonstrate an uncomfortable truth. Conventional MFA may make an attack more difficult, but it does not necessarily establish that the person logging in is actually the authorized employee.

Token was designed to solve that identity problem. Rather than asking whether someone knows a password, possesses a phone, or is willing to approve a notification, Token establishes biometric assured identity. It verifies that the authorized person is physically present, that the assigned Token device is present, and that the authentication request is coming from the legitimate destination. The result is not simply another factor. It is cryptographic proof that the correct person is at the correct device and is accessing the correct service.

How Attackers Bypass Conventional MFA

Prompt bombing is one of the simplest examples. An attacker who has obtained an employee’s password repeatedly sends authentication requests to the employee’s phone. Eventually, the employee may approve one because they are distracted, confused, or simply trying to stop the notifications. Token removes that decision entirely. There is no unexpected approval request and no prompt that can be accepted by mistake. Authentication requires the employee’s fingerprint on the assigned Token device while the device is physically near the computer or mobile system requesting access.

SIM swapping and telecommunications interception exploit a different weakness. SMS authentication assumes that control of a phone number is evidence of identity. Attackers defeat that assumption by transferring the victim’s number to another SIM or intercepting messages as they travel through telecommunications infrastructure. Token does not rely on a phone number, text message, carrier, or remotely delivered code. Its private cryptographic credential remains inside the Token device, so there is nothing useful for an attacker to redirect or intercept.

Adversary in the middle phishing is more sophisticated but follows the same underlying pattern. The attacker places a malicious proxy between the employee and the legitimate login service. The employee sees a convincing page, enters a password, and completes the MFA request. The attacker then captures the resulting credentials or session. Token prevents this by cryptographically binding authentication to the legitimate domain. A fake website cannot collect a Token credential and forward it elsewhere because the Token device will only sign the authentication challenge for the domain with which that credential was originally registered.

Modern phishing tools automate this entire process. They can reproduce enterprise login pages, relay credentials, generate authentication prompts, and capture sessions in real time. These kits have lowered the technical barrier so dramatically that criminals no longer need to build complex infrastructure themselves. Token removes the very elements these tools are designed to capture. There is no code to enter, no push notification to approve, no shared secret to relay, and no remotely available biometric. The attacker encounters a cryptographic process that requires the legitimate domain, the registered physical Token device, and the authorized employee’s fingerprint.

Help desk social engineering presents another challenge. Attackers may impersonate employees and request password resets, MFA resets, or enrollment of replacement devices. This is why biometric assured identity must extend beyond the login screen. Organizations using Token should require strong identity verification for sensitive support actions, including privileged account recovery and the enrollment of a new Token device. A help desk process should never replace biometric identity assurance with a few personal questions or a convincing phone call.

Some attacks occur after authentication rather than during it. OAuth consent phishing may persuade an employee to authorize a malicious application, while session hijacking may allow an attacker to steal an already authenticated browser session. Token greatly reduces the ability to enter an account using stolen credentials, but strong authentication does not replace application governance, endpoint security, session controls, privilege management, or continuous monitoring. Credible security depends on using the correct control for each attack surface. Token closes the identity and authentication gap that conventional MFA continues to leave open.

Three Form Factors with One Security Architecture

Employees do not all work in the same way. Some remain at dedicated workstations, some move between departments or facilities, and others travel or work remotely. Token therefore provides biometric assured identity through three separate form factors: Token Node, Token Wearable, and Token Portable.

Token Node provides a compact form factor for wrist, back of phone, key fob and other locations where a dedicated biometric identity device should remain part of the employee’s normal workflow. Token Wearable keeps the authenticator physically with the employee throughout the day, making secure access feel natural rather than requiring another device to be found or retrieved. Token Portable gives employees a convenient option that can simply sit on a desk for wireless use.

Although the physical designs are different, all three products work in the same way. Each is wireless. Each requires the authorized employee’s fingerprint. Each provides proximity based authentication. Each protects cryptographic credentials inside dedicated hardware. Each can bind authentication to the legitimate service or domain. Each is designed so biometric information remains within the device rather than being stored by the employer or transmitted across a network.

This gives the enterprise one consistent identity architecture while allowing employees and departments to choose the form factor that best fits the way they work.

Security That Employees Prefer

Security controls often fail when stronger protection creates slower workflows. Employees become frustrated, support calls increase, and users begin looking for shortcuts. Token reverses that tradeoff by making the stronger security experience dramatically faster.

A conventional enterprise login can take approximately 30 seconds as an employee enters a password, retrieves a phone, opens an authentication application, locates a code, responds to a notification, or repeats a failed attempt. Token can reduce that login process to approximately two seconds. The employee presents a fingerprint to the Token device and continues working.

That speed is an important reason employee acceptance is excellent. Token does not ask employees to tolerate more friction in exchange for better protection. It provides stronger security and a substantially better login experience at the same time. Employees no longer need to interpret security prompts, copy codes, inspect suspicious notifications, or decide whether an authentication request is legitimate. The safest action becomes the easiest action.

From Possession To Assured Identity

Passwords attempt to prove what someone knows. Phones and conventional security keys attempt to prove what someone possesses. Token proves that the registered device is present and that the authorized human is using it.

That distinction matters because possession alone is not identity. A security key can be lost, shared, borrowed, or stolen. A phone can be compromised, replaced, manipulated through account recovery, or handed to another person. A push notification can be approved by anyone holding the device.

Token places biometric verification directly inside dedicated enterprise authentication hardware. The fingerprint does not simply unlock a consumer phone that then performs authentication. It activates the protected cryptographic credential inside the Token device itself. Something the employee has and something the employee is are combined inside one secure device.

The employee does not need to become a phishing expert. The employee does not need to determine whether a prompt is legitimate. The employee does not need to copy a code or rely on a personal phone. Token verifies the person, the physical device, the employee’s proximity, and the legitimate destination before access is granted.

The Front Door Should Know Who Is Entering

Enterprises spend enormous sums detecting attackers after they have entered the network. Detection and response will always remain necessary, but organizations should not accept weak authentication as inevitable.

When a criminal logs in with a stolen password and an intercepted code, the system has not authenticated an employee. It has authenticated two pieces of compromised information. When someone approves an attacker’s push notification, the system has not established identity. It has merely recorded a human response.

Biometric assured identity sets a substantially higher standard. The authorized employee must be present. The registered Token device must be present. The employee’s fingerprint must match. The authentication request must be cryptographically valid. Only then does access proceed.

Token Node, Token Wearable, and Token Portable deliver that same protection through three distinct wireless form factors. Employees gain a login experience that can fall from approximately 30 seconds to approximately two seconds. Enterprises gain identity assurance that does not depend on codes, push notifications, personal phones, or a user’s ability to recognize a perfect fake.

Attackers are no longer breaking in. They are logging in. The answer is not another prompt. It is certainty about who is actually at the door.

This keeps the authentication architecture and positioning consistent with the earlier Token material while making the piece read more like a cohesive executive article.