MFA: The Second Lock That Hackers Can Still Pick
Multi-factor authentication blocks most stolen-password attacks — but not all of them. Here is how attackers get around it, and what actually holds up.
4 min readBeginner Aug 7, 2026
Explain Like I'm Not a Hacker
MFA is like a guard who checks a second ID after your password. It stops strangers cold, but it can still be fooled — hand that second ID to someone pretending to be the guard, or let someone reuse your badge after you've already walked through, and the guard never notices.
The 30-second explanation
A password alone is a single lock. Multi-factor authentication adds a second one, usually a code from an app or a tap on your phone, and it stops the vast majority of automated password-guessing attempts cold. It can't stop you from being talked into opening that second lock yourself, though. Attackers now build fake sign-in pages that sit between you and the real service. Type your password and your one-time code into one of these, and both get quietly forwarded straight through, so the attacker ends up holding a valid, already-approved session instead of just your password.
How it works
- 1
1. You
You open a link and land on a convincing sign-in page — same branding, same layout, a domain close enough to fool a quick glance.
- 2
2. Fake page
The page acts as a reverse proxy, quietly forwarding your username, password and MFA code to the real service the moment you type them.
- 3
3. Real service
The real service checks the password and code, finds them genuine, and issues a normal, valid session cookie back through the proxy.
- 4
4. Attacker
The attacker copies that session cookie and drops it into their own browser, signing in as you without ever needing your password or code again.
Multi-factor authentication proves who you are in more than one way: something you know, like a password, and something you have, like your phone or a hardware key. It's one of the strongest everyday protections you can turn on — it stops the overwhelming majority of attacks that rely on nothing but a stolen or guessed password. Attackers have adapted around it instead of through it. Some build a fake sign-in page that behaves exactly like the real one and just relay everything you type, including your one-time code, straight through to the genuine service as you enter it. Others don't bother tricking you at all. They go after the session created after you sign in — a stolen session cookie or access token lets them act as you without ever needing to see your password or your code.
Real-world example
Say you get a message claiming your account has a security problem, with a link to sign in and confirm it's you. The page looks right: same logo, same layout, a URL close enough that you don't look twice. You type your password, then the six-digit code from your authenticator app. The page has been relaying both to the real sign-in service the whole time, and it just captured the session cookie that service handed back. Your dashboard loads normally. Nothing looks wrong. Days later your account starts sending messages you never wrote, because the attacker has been using that stolen session alongside you this whole time. Not every version needs a fake page at all — an attacker who already has your password can just trigger a flood of push-approval requests to your phone at 2am, betting that irritation or a half-asleep tap gets one of them through.
How to spot it
A prompt you didn't request
An MFA approval request or one-time code text arrives while you're not signing in anywhere.
A flood of prompts in a row
Several push notifications arriving back to back, sometimes at an odd hour, is a known pressure tactic called MFA fatigue.
A code request on a linked page
You reached the sign-in page by clicking a link in an email, text or chat message, instead of typing the address yourself or using a saved bookmark.
A sign-in alert from somewhere new
A notification about access from an unfamiliar device, browser or location arriving right after you signed in normally.
What to do
- 1Never approve an MFA prompt you did not start — deny it, then change your password and review recent sign-in activity for the account.
- 2If a page asks for your password and then a code in the same flow, close it and navigate to the site directly instead of using the link that brought you there.
- 3Where it's offered, switch from SMS codes or push notifications to a phishing-resistant method such as a passkey or a FIDO2 security key, and enable number-matching on push approvals if your organisation supports it.
Stay curious. Stay safer.
This is one piece of a bigger picture. Explore more real-world examples, concepts and tips to build your cybersecurity awareness.
Keep reading
- Attacks
Phishing: How a Simple Email Can Lead to a Big Problem
4 min read - Credential Attacks
Credential Theft: How One Stolen Password Opens Every Door
4 min read - Fundamentals
DNS: The Invisible System Behind Every Click
2 min read - Attacks
Ransomware: What Really Happens When Hackers Lock Your Files
4 min read