Attackers now bypass two-factor authentication through techniques that intercept the session token by placing themselves between the user and the legitimate service.
For several years, the message from cybersecurity experts has seemed clear: activate two-factor authentication and you will be protected. Millions of businesses and individuals have followed this advice. And this protection is very real. Until the attackers adapt.
A technique documented by ESET researchers, called EvilTokens, illustrates this evolution. The principle is simple. Instead of trying to steal your password or bypass your OTP code, the attacker inserts himself between you and the legitimate authentication service. It presents you with a real Microsoft or Google login page, intercepts the session token the moment you log in, and uses that token to access your account. Without ever knowing your password, without triggering an alert. The irony: the attack works even if you have activated the double factor.
This type of technique, known as Adversary-in-the-Middle (AiTM), is not a laboratory curiosity. Since March 2024, campaigns exploiting a close variant, device code phishing, have been detected in Microsoft 365 environments in Europe. The stolen token can remain valid for days if no one manually revokes access.
The most immediate consequence concerns professional messaging and associated collaborative tools. When an attacker takes control of an email box, he is not only looking for sensitive data. There he finds commercial agreements, bank details, clear passwords sent by negligence, HR exchanges. He also finds an identity to usurp, intended for suppliers, collaborators, colleagues. With this identity, he can trigger fraudulent transfers, compromise other accounts, or prepare a larger-scale attack by taking the time to observe the organization’s habits.
If your email account was compromised tonight, how long would it take your cyber team to notice? In most SMEs, the honest answer is several days, sometimes several weeks. This is more than the time the attacker needs to cause significant harm.
Faced with this development, several concrete measures exist. The first is to opt, when possible, for phishing-resistant authentication methods, such as physical security keys (passkeys, FIDO2) rather than SMS or traditional TOTP applications. These methods do not pass an interceptable token. The second is to monitor unusual connections, including access from unexpected locations or sessions opened from unknown devices. The third is to train employees not to recognize fake login pages, which is becoming increasingly difficult, but to adopt reflexes to report when something seems unusual.
European regulations are pushing in this direction. NIS2, which now applies to a wide spectrum of companies in France, imposes reinforced requirements in terms of identity management and incident detection. The French transposition is in progress. However, for companies, regulatory compliance should not be the only driver, technology is improving faster than legislative timetables and the risk for the business is very real.
It’s time to move away from the idea that strong authentication is a checkbox once and for all. It remains necessary. It is no longer sufficient.
Fragility is not about being attacked. It’s not knowing it in time.