Authentication Intelligence

Every breach that
legacy MFA couldn't stop,
but MFA 2.0 would have.

Expert analysis of real-world authentication failures — and what phish-proof MFA 2.0 would have changed. Published by Al Lakhani, Founder of IDEE GmbH.

Latest Reports

Advanced NHS Breach: Stolen Credentials Gave Tokens That No MFA Could Block
Stolen credentials let attackers into Advanced, the NHS software supplier. Live session tokens then enabled ransomware that disrupted hospitals and ambulance services. Device-bound keys would have stopped the first step.
Costa Rica Conti Attack: Stolen Credentials Gave Up Live Tokens Resulting In Instant Access
Conti reached Costa Rican government systems through compromised remote-access credentials. The resulting session tokens required no further proof, enabling ransomware deployment across agencies.
Costa Rica CCSS Hive Attack: Stolen Credentials Created Reusable Sessions
Attackers used stolen employee credentials to reach Costa Rica's social security agency without a second factor. The resulting sessions allowed direct lateral movement and encryption.
Nelnet Breach: Unknown Entry Point Leaves MFA Claims Speculative
Nelnet disclosed exposure of borrower records but supplied no entry method. Without a documented login or token, no authentication factor can be evaluated.
Twitter API Scrape Hit 5.4 Million Accounts With No Login Attempted
Attackers queried an unprotected internal endpoint that returned email addresses and phone numbers with zero authentication checks. No credentials, sessions, or MFA factors were involved at any point.
Shutterfly ransomware: stolen credentials gave attackers an instant reusable session
Attackers used stolen credentials for direct login to Shutterfly systems, then operated inside an active session that required no further checks for data theft or ransomware deployment.
T-Mobile 2021: Brute Force on an Exposed Gateway Reached 76 Million Records
Attackers brute-forced an unprotected GPRS testing gateway, then used active sessions to reach customer databases. Device-bound credentials would have eliminated the remote credential attack surface on the first hop.
Kering Breach: Stolen Credentials Gave ShinyHunters Direct Access to Customer Data
ShinyHunters reached Kering records through reused credentials that produced a reusable session token. Device-bound keys would have blocked that first login because signatures must come from hardware the attacker never…
Cream Finance Lost $130M to Contract Logic No MFA Could Reach
Attackers drained Cream Finance pools through manipulated collateral checks inside smart contracts. No credentials or second factors existed for any authentication layer to protect.
Robinhood Breach: One Support Call Bypassed Every Login Control
A single phone call to Robinhood support granted attackers access to seven million customer records. Device-bound credentials would have made that transfer impossible.
JBS Paid $11M After One Set of Remote Access Credentials Worked
REvil reached JBS plants through valid remote access credentials and later moved laterally with harvested sessions. Device-bound signatures would have blocked the first step.
Kaseya VSA: Zero-Day Bypassed Auth Before Any MFA Could Apply
REvil reached 1,500+ organizations through a zero-day that let malicious updates run without credentials or MFA. Device-bound keys cannot close a flaw that sits before any login step occurs.
Facebook's 533 Million Records: An API Authorization Failure, Not a Login Problem
Attackers scraped 533 million Facebook records through a Contact Importer endpoint that accepted queries without verifying any relationship to the requested data. No login occurred.
Colonial Pipeline: One Reused VPN Password Shut Down 45% of East Coast Fuel
DarkSide used a single reused password from a dormant VPN account to reach Colonial Pipeline's network. No second factor existed at login, giving attackers an authenticated session they used to deploy ransomware.
SolarWinds: Password Spraying Success Resulted in the SAML Key Theft
APT29 reached SolarWinds through password spraying on weak admin accounts. Once inside the build system they inserted SUNBURST, then used stolen SAML signing keys to forge access across customer environments.
Oldsmar Hack: Shared TeamViewer Password Gave Full SCADA Control
A shared TeamViewer password let an attacker reach the SCADA workstation and change sodium hydroxide setpoints. Device-bound credentials would have required the enrolled hardware itself, not a reusable secret.
CNA Financial: Phishing Malware Harvested Sessions After Login
Phishing delivered malware that stole already-authenticated sessions at CNA Financial. Device-bound credentials would have blocked the initial foothold that made later movement possible.
Tchap Breach: Why Account Recovery Social Engineering Defeats Legacy MFA
Attackers gained Tchap access by convincing a user or support process to hand over an account. Legacy second factors attached to that account offered no protection once control transferred.
Workday Breach: Device-Bound Keys Eliminate What Employees Can Read Aloud
Attackers obtained Workday-linked CRM access by persuading employees to supply credentials over calls. Device-bound credentials close this vector because no readable secret exists to transfer.
Lapsus$ Breaches: Stolen Passwords Allowed Access To Microsoft, Samsung, Ubisoft
Lapsus$ used previously stolen passwords to log into Microsoft, Samsung, and Ubisoft. The resulting SAML tokens granted broad access across federated systems without additional authentication.
Lapsus$ Nvidia Breach: One Set of Credentials Opened Source Repositories
Lapsus$ used stolen employee credentials to log directly into Nvidia systems and exfiltrate source code. The login produced reusable sessions with no hardware boundary.
Lapsus$ Okta Breach: Social Engineering Turned Support Access Into Tenant Visibility
Attackers socially engineered an Okta employee for credentials and live approval to the support portal, exposing customer tenant metadata without taking federation tokens or customer sessions.