What MFA Actually Does — and Why Your Account Can Still Get Hacked

Published on 27 September 2026 at 20:15

Multi-factor authentication, or MFA, has become one of the most common ways to add another layer of protection to an online account.

Instead of relying only on a password, MFA asks you to prove your identity with more than one factor. That can include something you know, such as a password or PIN; something you have, such as your phone or a security key; or something you are, such as your fingerprint or face. Microsoft Support

For most people, that extra step is worth it. If someone steals or guesses your password, MFA can still stop them because they may not have access to the second form of verification.

But MFA is not impossible to get around. Attackers have found ways to target the person using the account instead of trying to break the security system itself.

MFA Fatigue Can Turn Notifications Into a Weapon

One method is called MFA fatigue, sometimes called push bombing.

This happens when an attacker repeatedly sends authentication requests to someone’s phone, hoping that the person eventually approves one just to make the notifications stop. CISA has documented attacks where users were bombarded with MFA prompts until they approved one by accident or simply wanted the requests to go away. CISA

That is why an MFA notification you did not trigger should never be ignored or automatically approved.

If your phone suddenly starts receiving repeated login prompts and you are not trying to sign in, treat that as a warning that someone may already have your password.

Session Hijacking Can Bypass the Login Screen

Another threat involves session cookies.

When you log into a website, the browser may save a session token or cookie so that you do not have to enter your password and MFA code every time you open another page.

If malware or a phishing attack steals that authenticated session token, an attacker may be able to reuse it and access the account without going through the normal login process again.

Recent phishing campaigns have used fake login pages that act as a proxy between the user and the real website. The victim enters the correct username, password, and MFA information, while the attacker captures the authenticated session token behind the scenes. Cloudflare

In other words, the MFA system may have worked correctly — but the attacker stole the proof that the user had already passed it.

SMS Codes Have Their Own Risks

MFA through text messages is still better than using only a password, but it has weaknesses.

One example is SIM swapping, where an attacker convinces or tricks a mobile carrier into transferring a victim’s phone number to a device or SIM they control. Once that happens, verification codes sent by text message may go to the attacker instead of the real account owner.

This is one reason authenticator apps, passkeys, and physical security keys are increasingly recommended when they are available. Passkeys, for example, are designed to be resistant to phishing because they are tied to the legitimate website or application. Microsoft Support

MFA Still Matters

Even with these risks, I still think MFA is absolutely necessary.

The fact that attackers work so hard to bypass it shows how much protection it adds. A stolen password by itself may not be enough to access an account when MFA is turned on.

The important thing is to stay alert. Do not approve login notifications you did not request. Pay close attention to website URLs before entering passwords or verification codes. Be cautious if someone asks you to read them a security code, and use stronger authentication methods such as authenticator apps, passkeys, or security keys when possible.

MFA is not a force field that makes an account impossible to hack. It is another layer between your information and the person trying to steal it.

And sometimes that extra layer is exactly what keeps an attacker out.