Multi-factor authentication remains the highest-value security control a small business can turn on. It is also no longer a complete answer. Two techniques are now routine:
Adversary-in-the-middle phishing. A convincing fake login page relays your credentials and MFA code to the real site in real time, then steals the resulting session cookie. The attacker is now signed in as you, without needing your password again.
Prompt bombing. Repeated push notifications at 2am until someone taps approve to make it stop.
What we see afterwards
Almost always the same thing: mailbox rules created to hide replies, then a genuine-looking email to a customer with new bank details. The money goes and it rarely comes back.
What actually helps
- Number matching rather than simple approve/deny prompts.
- Conditional access limiting sign-in to expected locations and compliant devices.
- Alerting on new mailbox rules and impossible-travel sign-ins. This is how you catch it in hours rather than weeks.
- A payment process that doesn't rely on email. Any change of bank details gets verified by phone on a previously known number, no exceptions.
- Passkeys or hardware keys for the accounts that matter most.
We monitor for these signals on the tenants we manage and have a compromise remediation process ready to run when one trips.