Your MFA Worked. The Attacker Got In Anyway.

  • The 2026 Verizon Data Breach Investigations Report documents a pattern it calls authentication bypass: attackers stealing session tokens and OAuth credentials to walk past MFA entirely, because MFA protects the login event and does nothing to protect the session afterward.
  • SpyCloud recaptured 8.6 billion stolen session cookies from criminal underground sources in 2025 alone, a concrete number behind a trend most security teams already sense but have not quantified.
  • Traditional identity systems verify a person once at sign-in, then assume the session stays in the right hands until sign-out or timeout, creating three exploitable gaps: no session continuity, no presence awareness, and a persistent, phishable attack surface.
  • Closing the gap requires continuously re-verifying presence throughout the session, not just strengthening the login, which is a structurally different problem than adding another MFA factor.

Every additional MFA factor an organization adds strengthens one moment: the login. Attackers have adapted accordingly. The 2026 Verizon DBIR's newest finding is that stolen session tokens and OAuth credentials now let attackers bypass MFA entirely, walking into an already-authenticated session without ever touching a password or a push notification.

This piece explains the finding, why it matters even for organizations that already require MFA everywhere, and what actually closes the gap.

What the 2026 DBIR's Authentication Bypass Finding Actually Says

Attackers are increasingly stealing session tokens and OAuth credentials, using techniques like CitrixBleed 2 and Device Code Authentication phishing against Microsoft 365, to walk past MFA entirely rather than trying to defeat it directly.

The Verizon 2026 DBIR, published May 19, 2026, documents this pattern because MFA protects the login event and does nothing to protect the session that follows it, an independent, third-party validation of a gap security teams have long suspected but rarely had a named report to point to.

The scale behind this is concrete, not anecdotal:

8.6 billion stolen session cookies were recaptured from criminal underground sources in 2025 alone. (SpyCloud, 2026 Identity Exposure Report)

Credential abuse has not disappeared as a factor either. It dropped to 13% as an initial breach access vector for the first time in the DBIR's 19-year history, but it still appears across the full attack chain in 39% of all breaches, attackers get in via a vulnerability, then pivot to credential dumping and password harvesting to move laterally and escalate privileges. Credentials are the connective tissue of an attack now, not just the front door.

Why This Is the Same Old Gap at a Bigger Scale

Traditional identity systems have always made the same assumption, that a session verified once at sign-in stays trustworthy until sign-out, and that assumption creates three specific gaps.

No session continuity: after sign-in, nothing confirms the same person is still present, so a stolen session token grants full access to whoever holds it. No presence awareness: systems cannot tell when a user walks away, leaving live sessions exposed to anyone nearby. A persistent attack surface: as long as passwords exist anywhere in the chain, they can be phished, guessed, or replayed, and add-on MFA reduces risk without eliminating it.

Trust granted once is trust misplaced. The 2026 DBIR simply gives that older architectural problem a current, quantified name.

Why Adding More MFA Does Not Close This Gap

A stronger login, a hardware key, a biometric check, a push prompt, still only answers who is signing in, not whether it is the same person five minutes later.

One in three users approve fraudulent MFA prompts when distracted (Microsoft Security Research), which is exactly the kind of failure push-based MFA is prone to. Phishing-resistant MFA as a category blocks over 99% of identity-based attacks, even when the attacker has the correct username and password (Microsoft Digital Defense Report 2025), a strong number, and one that describes the login event specifically, not what happens to the session afterward.

What Actually Closes the Session Gap: Presence, Not Just Identity

Closing the gap requires continuously re-verifying that the authenticated person is still physically present, not just re-checking their identity, since presence and identity are different problems.

Proximia's architecture separates the two: a live, liveness-checked biometric confirms identity once at sign-in, then a trusted device, the XiFi Card or the user's phone, maintains persistent proximity for the duration of the session through mutual, continuously verified trust. When the user moves outside the configured proximity zone, the session locks within seconds, and re-entry requires the biometric again.

This protects the local Windows, RDP, and VDI session specifically. A separate federated web application's session, an open Microsoft 365 browser tab, for example, is governed by that application's own token lifetime once sign-in completes; Proximia's continuous protection does not reach into a session it does not control after handoff. Scoping the claim this precisely is what keeps it true under scrutiny.

What This Means for Security Leaders Right Now

If your MFA strategy assumes a strong login is enough, the 2026 DBIR data says otherwise, and closing the gap is now a session-architecture question, not just an authentication-strength question.

Trust granted once is trust misplaced, and the fix is not a fourth factor at the door. It is a session that stays tied to a physically present, verified person for as long as it remains open.

Ready to Close the Gap?

See how continuous, presence-aware authentication protects the session, not just the sign-in. Schedule a demo at proximia.com/contact.

Frequently Asked Questions

Scroll to Top