MFA bypass attacks using phishing toolkits like Sneaky 2FA, EvilTokens, and EvilProxy are actively targeting US small businesses to steal Microsoft 365 credentials and session tokens, proving that MFA alone cannot stop determined attackers. Small business owners must layer additional controls like conditional access policies and session monitoring to block these threats.
**MFA Bypass Attacks Target US Small Businesses & Critical Router Flaws Exposed**
TP-Link Omada users face urgent security concerns with 15 vulnerabilities discovered in their router and network management systems that could enable complete network hijacking. Meanwhile, critical patches have been released for Veeam (including a perfect 10.0 severity flaw), Django, and Terraform that require immediate attention.
In a concerning development, AI-powered phishing campaigns are creating disposable infrastructure so rapidly that traditional blocklists can no longer keep pace. This shift demands a move toward behavior-based detection and enhanced user training rather than relying solely on known-bad indicators.
Small businesses must prioritize layered defenses, immediate patching, and comprehensive employee training to protect against these evolving threats.
**Sources:** - https://cybersecuritynews.com/phaas-kits-targeting-us-organizations/ - https://cybersecuritynews.com/tp-link-omada-ztp-flaws/ - https://thehackernews.com/2026/08/veeam-terraform-mcp-django-patch.html - https://www.bleepingcomputer.com/news/security/how-ai-powered-phishing-killed-blocklists-for-good/
What do MFA bypass attacks mean for your small business?
Three phishing toolkits (Sneaky 2FA, EvilTokens, EvilProxy) are successfully stealing credentials from small and mid-size businesses despite MFA being enabled. These tools trick users into revealing session tokens, then use them to access company systems. The immediate business consequence is credential compromise and potential access to email, file storage, and connected applications. CISA and cybersecurity vendors report these attacks are accelerating. Your single most important action: enable conditional access policies in Microsoft 365 to require device compliance checks and geographic location verification. Add session monitoring to detect unusual sign-in patterns. Train staff to recognize phishing that requests token entry.
Key takeaways
- Sneaky 2FA, EvilTokens, and EvilProxy phishing kits bypass MFA by harvesting user session tokens through credential theft.
- MFA is a necessary first layer but not a complete defense; add conditional access policies and session monitoring to block attackers who obtain credentials.
- TP-Link Omada routers face 15 critical vulnerabilities; patch immediately to prevent network hijacking of your business infrastructure.
- AI-generated phishing campaigns change so fast that blocklists fail; shift to behavior-based detection and mandatory employee training.
Frequently asked questions
If we have MFA enabled, why are we still at risk from MFA bypass attacks?
MFA bypass attacks trick users into typing their credentials and session tokens into fake login pages. Once the attacker has the token, they log in directly without needing the second factor. MFA stops casual attackers but not sophisticated phishing that harvests the full authentication chain.
What is conditional access and how does it stop these attacks?
Conditional access is a Microsoft 365 feature that blocks logins from unusual locations, unmanaged devices, or suspicious sign-in patterns, even if the attacker has the correct password and token. It adds a second layer of verification that phishing alone cannot overcome.
Should we be worried about the TP-Link Omada vulnerabilities if we use those routers?
Yes. The 15 flaws in TP-Link Omada routers and management systems could allow attackers to take over your entire network. Patch all affected devices immediately and check TP-Link's security advisories for your specific models.
What should we train employees to do differently after this news?
Train staff to never type credentials or one-time codes into login pages, especially after clicking email links. Teach them to go directly to known URLs or use authenticator apps instead of SMS codes. This simple behavior change blocks most phishing toolkit attacks.