VFF - The signal in the noise
News

MFA Resets Become the New Attack Vector in Financial Services

louiswcolumbus@gmail.com (Louis Columbus)Read original
Share
MFA Resets Become the New Attack Vector in Financial Services

Financial services organizations are being compromised through voice phishing and MFA resets rather than password theft, according to CrowdStrike's 2026 threat report. Mutant Spider, the most active threat group targeting the sector, impersonates IT support over Microsoft Teams to convince employees to reset credentials and MFA, then registers attacker devices on corporate networks. This represents a structural shift in attack methodology that bypasses traditional password-based security controls.

  • Mutant Spider conducted the most successful attacks on financial services in the past 12 months using voice phishing over Microsoft Teams, not password theft
  • The group impersonates IT support, convinces employees to reset MFA, and registers attacker devices to gain persistent network access
  • Credential theft dropped to 13% of breach initial access vectors, while vulnerability exploitation rose to 31%, according to Verizon's 2026 report
  • Financial services faced 43% more hands-on-keyboard intrusions in 2025 compared to two years earlier, with ransomware operators naming 423 entities on leak sites

MFA, long considered a gold standard security control, is proving insufficient against sophisticated social engineering attacks that bypass password authentication entirely. Attackers are exploiting the legitimate MFA reset process itself as an attack vector, meaning organizations cannot rely on traditional credential-based defenses. This represents a fundamental shift in how financial institutions must approach access control and employee security training.

Financial services organizations must reassess their security architecture beyond MFA implementation. The attacks documented are low-cost, high-success operations that don't require zero-day exploits or advanced technical skills, making them economically attractive to both e-crime and state-sponsored actors. Organizations need to implement additional controls around credential reset processes, device registration, and token management to close these gaps.

  • MFA reset processes require additional authentication layers and approval workflows to prevent social engineering attacks
  • Device registration and token grant mechanisms need monitoring and restrictions independent of MFA status
  • Voice phishing over internal communication platforms like Microsoft Teams is now a primary attack vector requiring specific employee training and technical controls
  • OAuth token theft through legitimate authentication flows bypasses MFA entirely and grants persistent access without additional prompts

Monitor for increases in voice phishing attempts targeting IT support functions and credential reset requests. Track adoption of conditional access policies that restrict device registration and token grants based on risk signals. Watch for emerging phishing-as-a-service platforms like Kali365 that specifically target OAuth token capture through legitimate authentication flows.

Share

Our Briefing

Weekly signal. No noise. Built for founders, operators, and AI-curious professionals.

No spam. Unsubscribe any time.

Related stories

Seattle votes on data center moratorium as Amazon employees push back

Seattle votes on data center moratorium as Amazon employees push back

Seattle City Council will vote June 9th on a one-year moratorium on new data centers, just two months after companies proposed five large-scale facilities in the city. Amazon employees have joined other supporters in testifying for the moratorium, citing concerns about water consumption, electricity prices, and noise. The vote reflects growing tension between tech infrastructure expansion and local environmental and operational impacts.

by Hayden Fieldabout 24 hours ago· The Verge AI
OpenAI Launches Economic Research Exchange on AI's Job Impact

OpenAI Launches Economic Research Exchange on AI's Job Impact

OpenAI has launched the Economic Research Exchange, a platform designed to study artificial intelligence's effects on employment, productivity, and broader economic outcomes. The initiative opens applications for selected research projects that will examine AI's economic impact. The program represents a structured effort to generate empirical evidence on how AI deployment affects labor markets and economic performance.

about 24 hours ago· OpenAI
AWS Bedrock adds cross-region inference for EU compliance

AWS Bedrock adds cross-region inference for EU compliance

AWS has introduced cross-Region Inference (CRIS) on Amazon Bedrock, a managed capability that automatically routes AI model inference requests across multiple AWS regions within defined geographic boundaries. The feature allows European customers to access generative AI models and compute capacity while maintaining compliance with data protection regulations like GDPR. CRIS includes both global profiles that route to any supported AWS commercial region and EU-specific profiles designed for customers with regional data processing requirements.

by Hamza Usmaniabout 24 hours ago· AWS Machine Learning Blog
Anthropic Warns on Recursive Self-Improvement Even as Industry Races Ahead

Anthropic Warns on Recursive Self-Improvement Even as Industry Races Ahead

Anthropic announced that Claude now writes 80% of its code, highlighting progress toward recursive self-improvement, where AI systems create the next generation without human involvement. The company simultaneously warned that this capability poses control risks, as unintended model behaviors could compound across generations and become harder to understand. The announcement reflects broader industry momentum, with OpenAI, Google DeepMind, and well-funded startups like Recursive Superintelligence and Inherent all pursuing similar capabilities.

by Rocket Drew2 days ago· The Information