Skip to content

Build1 publisher3 min readPublished

MFA-relaying proxy kits make up 44.6% of phishing techniques in Microsoft's 2026 report

Microsoft's 2026 Digital Defense Report puts MFA-relaying proxy kits at 44.6% of phishing techniques, as phishing rose to 23% of its incident cases. SMS codes and push approvals pass straight through those proxies, so protecting company email now means passkeys or FIDO2 keys, starting with admins and finance staff.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • An adversary-in-the-middle page is a reverse proxy: the victim types a real password into the real sign-in page, approves a real MFA prompt, and the proxy keeps the returned session cookie.
  • Microsoft reports that 87.7% of phishing intrusions involved harvesting credentials or sessions.
  • Attackers with one working account go looking for more, with 52.2% of intrusions that began with valid accounts involving follow-on credential theft.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Any organisation whose second factor is an SMS code, an app code or a push approval stays open to the most common phishing technique in the report, even when staff follow every rule.
  • decision Passkey rollout becomes a sequencing decision: admins, finance, HR and payment approvers go first, without waiting to enrol the whole company.
  • cost Shorter sessions cost staff more frequent sign-ins. In return, a stolen session cookie stays usable for less time.

When a user approves a push prompt behind one of these kits, the approval reaches the real server. The proxy forwards whatever the user types, code included, in real time [9]. The server sends back a session cookie and the proxy keeps it [6]. The user followed every rule and still handed over a live session [9].

SMS codes, authenticator-app codes and push approvals still stop the older attack, where someone buys a leaked password and signs in from another country [9]. Against a relay they add nothing, because the code is just more text to forward [9]. FIDO2 security keys and passkeys work differently. The browser will not sign a challenge for a look-alike domain, so the proxy has nothing useful to pass along [10]. Microsoft's recommendation in the report is to move beyond traditional MFA and prioritise phishing-resistant methods [11].

Most of these figures come from a write-up by FanMail, a mail platform, which points to pages 33 and 45 of the report PDF [19]. FanMail offers SMS one-time passwords and TOTP codes as its second factor, and the post says plainly that neither is phishing-resistant [12]. I think that admission is the most useful sentence in it.

The 23% has two caveats. The report was published on 1 October and covers July 2025 to June 2026 [1][2]. The figure is a share of Microsoft's incident-response cases [3], so it describes intrusions serious enough to reach that team. Whether it carries over to a given tenant depends on how closely that tenant's attackers resemble the ones Microsoft's responders saw. The jump from 7% is roughly a 3.3-fold rise [1]. Over the same year, cases with no identified entry point fell from 25% to 14% [4]. Suppose every newly explained case had been phishing all along. Better visibility would then cover 11 of the 16 points, and at least 5 points of the rise would have some other cause [2]. The post does not give a prior-year share for AiTM kits. The 44.6% shows relay kits lead this year, against 33.6% for standard URL phishing and 12.9% for attachments, but it does not show how fast they grew [5].

The ways victims reach the proxy are changing too. Microsoft Defender for Office 365 caught more than 145 million QR code phishing attacks, and by April 2026, 79% of them were arriving inside PDFs [13]. The code gets scanned on a personal phone, outside every corporate control [13]. In more than 100 million attacks, the credential page sat behind a CAPTCHA. Automated scanners never get past it to see the page [14].

With device code phishing, there is no fake page at all. The lure sends people to Microsoft's real device sign-in page, and the attacker collects OAuth tokens afterwards [15]. A key bound to the site's address passes that check, because the address is genuine [3]. Session controls are the part of the advice that still applies there. According to the post, AiTM steals a session, and long-lived sessions with silent token refresh are what make it pay [18]. It recommends shortening sessions and alerting when the same session appears from a new network [18]. It also recommends starting passkeys or FIDO2 keys with admins, finance, HR and anyone who approves payments [17]. The fake help desk lure, a burst of junk email followed by a chat from a new account posing as IT support, goes after staff trust in their own support team [16].

What to watch

  • Microsoft publishing last year's AiTM share, the figure needed to show whether MFA-relaying phishing is actually growing.
  • Next year's unidentified-entry share: if it keeps falling while phishing holds near 23%, the visibility explanation for this year's jump weakens.
  • Whether FanMail adds passkey or FIDO2 sign-in alongside the SMS and TOTP second factors it now says are not phishing-resistant.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories