Webinar: How Attackers Bypass MFA and How Defenders Can Respond
Upcoming live webinar on July 8, 2026, hosted by BleepingComputer, explores how attackers bypass MFA—especially through Device Code phishing that leverages legitimate Microsoft login flows—within phishing, BEC, and account takeover attacks, and how defenders can use behavioral AI to detect unusual activity, automate investigations, and reduce response times. Presented by Dan Nickolaisen of Abnormal AI and Eric Danneker of Novant Health.

Webinar: How Attackers Bypass MFA and How Defenders Can Respond
OverviewMulti-factor authentication is a cornerstone of modern account security, but it is not a silver bullet. Adversaries are increasingly bypassing or abusing the very workflows that organizations rely on to keep systems secure. Phishing campaigns, business email compromise (BEC), and account takeover (ATO) attacks are evolving to leverage legitimate authentication processes, often without triggering traditional defenses. A new wave of techniques targets the authentication flow itself, creating persistent access without the need to steal passwords. This shift challenges security teams to rethink detection, response, and automation.
The Evolving Threat Landscape
- Phishing remains a primary attack vector, but attackers are shifting from credential theft to exploiting authorization workflows that grant tokens and access without exposing passwords.
- Access tokens obtained through compromised processes can sustain access to email, collaboration tools, cloud services, and corporate resources even when password monitoring is in place.
- Traditional defenses such as email filtering, credential monitoring, and MFA protections may not reveal these breaches until investigations begin after anomalous activity is observed.
- Modern threats increasingly blend phishing, BEC, and ATO tactics to abuse trusted services and legitimate login experiences, making early detection more difficult.
Device Code Phishing: A Growing Concern
- A notable technique gaining traction is Device Code phishing, where users are tricked into approving access using familiar, legitimate Microsoft authentication pages.
- Because the login flow involves a real authentication event and an MFA challenge, attackers can maintain long-term access without ever seeing or stealing user credentials.
- This approach exploits the trust users place in familiar interfaces and the legitimate appearance of OAuth and device authorization prompts.
Implications for Security Operations
- Conventional security controls that focus on credential theft or email content may miss these flows, leaving defenders with limited visibility until an account is already compromised.
- Security Operations Centers (SOCs) and incident response teams face higher volumes of subtle, legitimate-appearing activity that requires deeper investigation.
- There is a need for approaches that monitor behavior across accounts and services, rather than relying solely on signature-based alerts or static policy checks.
Behavioral AI as a Detection and Response Tool
- Behavioral AI analyzes patterns of normal versus unusual activity across accounts, communications, and device usage to identify anomalies that standard controls overlook.
- By modeling typical user behavior, these systems can flag deviations such as unexpected login times, unusual locations, atypical device fingerprints, or anomalous sequences of authentication events.
- Automation driven by behavioral insights can triage and accelerate investigations, reducing manual workload and shortening the time to detect genuine compromises.
What the Webinar Will Cover
- How Device Code phishing operates and why it can bypass traditional credential theft protections.
- Why contemporary phishing campaigns, BEC, and ATO attacks increasingly evade conventional email security controls.
- The operational challenges these attacks create for security operations centers and incident response teams.
- How behavioral AI can distinguish suspicious account activity from normal behavior and automate parts of the investigation process.
- Practical strategies for reducing response times and limiting the risk of account takeovers.
Learning Outcomes and Practical Benefits
- Earlier detection of compromised accounts by focusing on behavioral signals rather than solely on password-related events.
- Reduced investigation workload through automated triage and evidence gathering guided by behavioral patterns.
- Faster containment and remediation by triggering targeted responses when anomalies are detected in near real time.
- Improved resilience against attacks that abuse trusted services and legitimate authentication workflows.
Join the Discussion: How Defenders Can Respond More EffectivelyAttendees will explore methods to strengthen defenses against the latest phishing techniques that exploit identity, trust, and legitimate authentication flows. The session emphasizes proactive detection, faster investigations, and automated workflows that help security teams respond before attackers escalate a breach into a larger incident.
Registration InformationTo participate in the live session and gain insights into defending against modern MFA-evading techniques, register through the webinar link:Register now to secure your spot: http://event.on24.com/wcc/r/5380206/B300273406FDF2010A97D4B47248EB19?utmsource=bleepingcomputer&utmmedium=referral&utmcampaign=Abnormal&utmcontent=article
Event Context
- Topic emphasis: Abnormal AI, device code, MFA, phishing, webinar
- Focus: Detecting account compromise earlier, automating investigations, and reducing response times through behavioral analysis
Additional Context and Resources
- Abnormal AI offers insights into cognitive security approaches that leverage behavioral signals to identify unusual activity and communications that traditional controls may miss.
- The discussion highlights the importance of evaluating authentication workflows and the potential gaps that can be exploited by attackers who abuse legitimate processes.
Closing ThoughtsAs attackers increasingly target the authentication workflow itself, defenders must adapt by combining advanced behavioral analytics with automated response capabilities. By focusing on how accounts behave across devices, locations, and services, organizations can illuminate signs of compromise that raw credential data alone cannot reveal. The upcoming webinar provides a practical framework for identifying, investigating, and containing these modern threats, with an emphasis on reducing detection and remediation times through intelligent automation.


