MFA bypass attacks are now hitting small businesses through AI-generated voice calls and password spraying campaigns that exploit gaps in multi-factor authentication. Hackers behind the Balonx Sistema campaign combine fake banking pages with synthetic voices to steal credentials, while a separate attack generated 81 million login attempts in just two weeks.
Small business owners face critical cybersecurity threats this week. Hackers are using AI-generated voice calls with fake banking pages to bypass multi-factor authentication through a campaign called Balonx Sistema. Password spraying attacks have surged 155 times in the first half of 2026, with one campaign generating 81 million login attempts in two weeks, exploiting MFA gaps and legacy authentication.
Hundreds of Stripe merchant API keys were leaked on cybercrime forums, exposing payment processing capabilities. Businesses using Stripe should immediately rotate API keys and monitor for unauthorized transactions. CISA added four critical vulnerabilities to its exploited list, including macOS Screen Sharing, Microsoft SharePoint, and VMware vCenter flaws. Hackers are actively gaining root-level control through the macOS vulnerability.
Key takeaway: Multi-factor authentication alone is no longer sufficient. Businesses must layer defenses, maintain current patches, verify suspicious contacts, and rotate API keys regularly to protect against these evolving threats.
Why are MFA bypass attacks succeeding against small business defenses?
Password spraying attacks have surged 155 times in the first half of 2026, targeting weak or reused credentials that MFA alone cannot stop. The Balonx Sistema campaign uses AI-generated voice calls paired with fake banking pages to manipulate employees into revealing codes or credentials. CISA flagged four critical vulnerabilities this week, including macOS Screen Sharing (CVE data available via CISA alerts) and Microsoft SharePoint flaws that give attackers root-level control. Small businesses relying only on MFA face real downtime risk. Action: Rotate passwords, require longer passphrases, patch macOS and SharePoint immediately, enable conditional access rules, and train staff to verify caller identity before sharing any authentication codes.
Key takeaways
- MFA alone stops password attacks only when credentials remain secret. AI voice calls now trick employees into revealing codes, making layered defenses (conditional access, phishing detection, endpoint patching) non-negotiable.
- CISA added four exploited vulnerabilities this week. macOS Screen Sharing, Microsoft SharePoint, and VMware vCenter flaws allow remote root access. Patch within 48 hours if you use these tools.
- Stripe merchant API keys leaked on cybercrime forums this week. Rotate API keys immediately, audit transaction logs for the past 30 days, and enable API IP whitelisting to reduce exposure.
Frequently asked questions
If we already use MFA, are we protected from the Balonx Sistema attack?
No. The attack targets employees directly with AI voice calls that trick them into revealing MFA codes before they can be used. MFA is still essential, but it must be paired with conditional access rules, phishing detection, and staff training on caller verification. Attackers cannot bypass MFA if the code is never shared.
What should we do if we use Stripe for payment processing?
Rotate all Stripe API keys immediately and review transaction logs for the past 30 days to spot unauthorized charges or API access. Enable IP whitelisting in Stripe's dashboard to restrict API calls to your office and known vendor networks. Monitor your account for the next 90 days.
Do we need to patch our macOS and SharePoint systems right now?
Yes. CISA flagged four critical vulnerabilities this week, and attackers are actively exploiting the macOS Screen Sharing flaw to gain root access. Patch macOS and SharePoint within 48 hours. If you cannot patch immediately, disable the affected services (Screen Sharing remote access, SharePoint external sharing) until patches are applied.
What is password spraying and why did attacks surge 155 times?
Password spraying is when attackers try common passwords across many accounts instead of guessing one password repeatedly. One campaign sent 81 million login attempts in two weeks. Attackers succeed when businesses use weak, reused passwords or fail to monitor login failures. Require passphrases of 16+ characters and enable login alerts for failed attempts above normal thresholds.
Sources
- https://cybersecuritynews.com/hackers-use-ai-voice-calls/
- https://www.bleepingcomputer.com/news/security/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
- https://cybersecuritynews.com/hundreds-of-leaked-stripe-merchant-keys/
- https://thehackernews.com/2026/08/critical-macos-sharepoint-vcenter-and.html
- https://cybersecuritynews.com/hackers-exploiting-macoss-screen-sharing-service/