- The 2026 Verizon Data Breach Investigations Report documents a pattern it calls authentication bypass: attackers stealing session tokens and OAuth credentials to walk past MFA entirely, because MFA protects the login event and does nothing to protect the session afterward.
- SpyCloud recaptured 8.6 billion stolen session cookies from criminal underground sources in 2025 alone, a concrete number behind a trend most security teams already sense but have not quantified.
- Traditional identity systems verify a person once at sign-in, then assume the session stays in the right hands until sign-out or timeout, creating three exploitable gaps: no session continuity, no presence awareness, and a persistent, phishable attack surface.
- Closing the gap requires continuously re-verifying presence throughout the session, not just strengthening the login, which is a structurally different problem than adding another MFA factor.
Every additional MFA factor an organization adds strengthens one moment: the login. Attackers have adapted accordingly. The 2026 Verizon DBIR's newest finding is that stolen session tokens and OAuth credentials now let attackers bypass MFA entirely, walking into an already-authenticated session without ever touching a password or a push notification.
This piece explains the finding, why it matters even for organizations that already require MFA everywhere, and what actually closes the gap.
What the 2026 DBIR's Authentication Bypass Finding Actually Says
Attackers are increasingly stealing session tokens and OAuth credentials, using techniques like CitrixBleed 2 and Device Code Authentication phishing against Microsoft 365, to walk past MFA entirely rather than trying to defeat it directly.
The Verizon 2026 DBIR, published May 19, 2026, documents this pattern because MFA protects the login event and does nothing to protect the session that follows it, an independent, third-party validation of a gap security teams have long suspected but rarely had a named report to point to.
The scale behind this is concrete, not anecdotal:
8.6 billion stolen session cookies were recaptured from criminal underground sources in 2025 alone. (SpyCloud, 2026 Identity Exposure Report)
Credential abuse has not disappeared as a factor either. It dropped to 13% as an initial breach access vector for the first time in the DBIR's 19-year history, but it still appears across the full attack chain in 39% of all breaches, attackers get in via a vulnerability, then pivot to credential dumping and password harvesting to move laterally and escalate privileges. Credentials are the connective tissue of an attack now, not just the front door.
Why This Is the Same Old Gap at a Bigger Scale
Traditional identity systems have always made the same assumption, that a session verified once at sign-in stays trustworthy until sign-out, and that assumption creates three specific gaps.
No session continuity: after sign-in, nothing confirms the same person is still present, so a stolen session token grants full access to whoever holds it. No presence awareness: systems cannot tell when a user walks away, leaving live sessions exposed to anyone nearby. A persistent attack surface: as long as passwords exist anywhere in the chain, they can be phished, guessed, or replayed, and add-on MFA reduces risk without eliminating it.
Trust granted once is trust misplaced. The 2026 DBIR simply gives that older architectural problem a current, quantified name.
Why Adding More MFA Does Not Close This Gap
A stronger login, a hardware key, a biometric check, a push prompt, still only answers who is signing in, not whether it is the same person five minutes later.
One in three users approve fraudulent MFA prompts when distracted (Microsoft Security Research), which is exactly the kind of failure push-based MFA is prone to. Phishing-resistant MFA as a category blocks over 99% of identity-based attacks, even when the attacker has the correct username and password (Microsoft Digital Defense Report 2025), a strong number, and one that describes the login event specifically, not what happens to the session afterward.
What Actually Closes the Session Gap: Presence, Not Just Identity
Closing the gap requires continuously re-verifying that the authenticated person is still physically present, not just re-checking their identity, since presence and identity are different problems.
Proximia's architecture separates the two: a live, liveness-checked biometric confirms identity once at sign-in, then a trusted device, the XiFi Card or the user's phone, maintains persistent proximity for the duration of the session through mutual, continuously verified trust. When the user moves outside the configured proximity zone, the session locks within seconds, and re-entry requires the biometric again.
This protects the local Windows, RDP, and VDI session specifically. A separate federated web application's session, an open Microsoft 365 browser tab, for example, is governed by that application's own token lifetime once sign-in completes; Proximia's continuous protection does not reach into a session it does not control after handoff. Scoping the claim this precisely is what keeps it true under scrutiny.
What This Means for Security Leaders Right Now
If your MFA strategy assumes a strong login is enough, the 2026 DBIR data says otherwise, and closing the gap is now a session-architecture question, not just an authentication-strength question.
Trust granted once is trust misplaced, and the fix is not a fourth factor at the door. It is a session that stays tied to a physically present, verified person for as long as it remains open.
Ready to Close the Gap?
See how continuous, presence-aware authentication protects the session, not just the sign-in. Schedule a demo at proximia.com/contact.
Frequently Asked Questions
Doesn't MFA already stop most attacks?
It stops most attacks aimed at the login event. The 2026 DBIR shows attackers increasingly bypassing it altogether by targeting the session that follows instead.
What is session hijacking, exactly?
It is the theft and reuse of a session token, cookie, or OAuth grant that represents an already-authenticated session, letting an attacker act as that user without ever needing the original password or MFA prompt.
Does this mean my current MFA is useless?
No. MFA remains valuable at the login event; the gap is specifically what happens to the session afterward, which MFA on its own does not address.
Does Proximia protect cloud application sessions like Microsoft 365?
Proximia continuously protects the local workstation, RDP, and VDI session. Sign-in protection, no password, no phishable prompt, extends to SAML-based applications, but the ongoing session for a federated web app like Microsoft 365 is governed by that application's own token lifetime once sign-in completes.
What is the difference between identity verification and presence verification?
Identity verification confirms who signed in, once, at the start of a session. Presence verification confirms someone is still physically there, continuously, for as long as the session stays open.




