Qteco
Services01 Sovereign Cloud02 NIS203 Security Check04 Investment05 References06 News07 Contact08
Client Portal Book a call
Cybersecurity

Why two-step verification does not stop this phishing

10 September 2026·Qteco Redactie
Why two-step verification does not stop this phishing

Researchers at CloudSEK gained access to the control panel of a phishing service built exclusively to target Microsoft 365. The panel held more than 5,100 stolen sets of credentials, including 474 sign-ins where two-step verification had genuinely been bypassed. Confirmed break-ins were recorded at 258 organisations across more than forty countries. The service is rented out as a subscription to criminals who never have to write a line of code themselves, and that is what makes this case awkward for smaller businesses: the technique is no longer reserved for advanced attackers.

How the attack works

A classic phishing email tries to steal your password. This attack goes a step further. The fake sign-in page sits between your employee and the real Microsoft sign-in page. Everything your employee types is passed on to Microsoft, so the sign-in genuinely succeeds: the user watches their own Outlook or Teams open and notices nothing. Meanwhile the attacker copies not only the password but the session cookie that Microsoft issues after a successful sign-in. With that cookie the attacker signs in without ever needing a code or an approval again. Two-step verification has not been broken, it has been skipped.

The service also uses a trick to switch off the strongest protection. If your account supports a physical key or a passkey, a small script makes sure that option never appears on the fake page, so the user falls back to a text message or an approval in the app. Traffic is routed through residential addresses in 69 countries, which makes the sign-in look to Microsoft like an ordinary user at home.

What this means for your organisation

Many organisations rolled out two-step verification over the past few years and treated that step as finished. That was reasonable, because it is still far better than a password alone. But a text message code or a tap on "Approve" in the Authenticator offers no protection against an attacker watching live. Organisations hit by campaigns like this usually find out only once mail is being forwarded, invoices are altered, or files disappear from SharePoint.

The risk is not evenly spread either. Accounts belonging to directors, finance staff and administrators are the most attractive targets, and those are precisely the people least inclined to change how they sign in.

What you can do this week

  • Turn on phishing-resistant sign-in for administrators, directors and the finance team: passkeys or hardware keys. They are tied to Microsoft's real address and simply do not work on a copied page.
  • Configure conditional access so that signing in only succeeds from devices you manage. A stolen cookie is then useless on the attacker's computer.
  • Shorten session lifetimes for accounts with extensive rights, and make sure you can revoke sessions centrally.
  • Check whether you have visibility of sign-ins from residential addresses and unusual locations, and who reviews them at night and at weekends.
  • Tell your team what is changing. An employee who knows that signing in now uses a key becomes suspicious the moment a page still asks for a text message code.

From measure to routine

The underlying lesson is not that two-step verification is pointless, but that security is not a project with an end date. Attackers move to the weakest link that still works, and right now that is the approval prompt in an app. A year from now it will be something else. Organisations that keep pace review their sign-in policy every quarter rather than once every three years.

We help clients introduce passkeys and conditional access in Microsoft 365, and monitor suspicious sign-ins afterwards. If you would like to know where your own sign-in policy stands today, arrange a conversation with one of our engineers. Background on this campaign is available at BleepingComputer.

Read also

Record Windows update round with two exploited flaws

Attackers take over routers through open admin access

Chrome flaw under active attack: restart your browser

Ready to run worry-free?

Book a no-obligation introduction. We map your IT and security and show where the difference lies.

Book a call