Authentication Intelligence

Every breach that
legacy MFA couldn't stop,
but MFA 2.0 would have.

Expert analysis of real-world authentication failures — and what phish-proof MFA 2.0 would have changed. Published by Al Lakhani, Founder of IDEE GmbH.

Latest Reports

Stop IEH-style fake M365 login credential theft
IEH’s fake M365 login page harvested workforce credentials. Phishing-proof device-bound MFA leaves that page nothing to steal before a mailbox session exists.
Gunra VDI abuse: where MFA 2.0 actually helps
Gunra AA26-222A stacked Fortinet auth bypass, VDI cookie theft, and a server OTP backdoor. See where phishing-proof MFA helps, and where it does not.
DGFiP lesson: phishing-proof agent and partner login so usurped IDs cannot mint trusted tax sessions
DGFiP’s 678,000-record hit used usurped agent and third-party logins. Stop stolen workforce IDs from minting sessions before live tax access begins.
Stop Entra Password Spray and MFA Fatigue: Closing Push-Approval Failures at Workforce Login
Where workforce Entra still accepts passwords plus approvable push, spray-and-fatigue remains a login-time failure. Phishing-proof MFA removes that surface.
Not all passkeys are created the same DEES
SpecterOps published more than twenty Pass-the-Passkey techniques. Sixteen bear on the choice of identity provider: six are IdP failures, three are passkey misuse, six need malware on PCs. RDP is the exception CBE stops.
Phishing-proof MFA stops vishing MFA code harvests
A five-week vishing wave hit 200+ orgs via spoofed logins. Phishing-proof, device-bound MFA removes the transferable secrets callers harvest.
Device-bound MFA stops UNC6671 vishing AiTM
UNC6671 coached hedge-fund staff onto AiTM logins via helpdesk vishing. Device-bound phishing-proof MFA blocks transferable secrets and fake enrollment; stolen SSO cookies remain a residual problem.
Stop Mirage2FA AiTM at the Microsoft 365 login
Mirage2FA proxied Microsoft 365 logins, relayed live MFA, then stole session cookies. Passkeys stop the relay; revoke and CAE handle cookies already issued.
Device-bound MFA stops Payroll Pirates at login
Payroll Pirates harvested Microsoft 365 sessions after users finished MFA. Device-bound phishing-proof auth refuses the AiTM proxy so the cookie never issues.
Phishing-proof MFA stops AiTM before a session exists
AiTM phishing relayed password and MFA into a live Microsoft 365 session. Device-bound login stops the harvest; unbound tokens still need protection after auth.
Device-bound MFA would have blocked Baroda email login
Bank of Baroda lost mailbox access to a weak password. Device-bound MFA would have blocked remote password-only login before file harvest began.
Device-bound MFA 2.0 would have blocked Greatness AiTM
Greatness PhaaS stole MFA-approved Microsoft 365 tokens via RingCentral-spoofed AiTM flows. Device-bound keys would have blocked the login path before any session issued.