22 documented legacy MFA failures — and counting.

Legacy MFA Hall of Shame

It got phished or bypassed.
Again.

A running record of every breach where SMS codes, OTP apps, and push notifications got bypassed, stolen, or simply ignored. No spin. Just receipts.

The Breach Log

Advanced NHS Breach: Credentials Then Live Tokens Let Ransomware Spread
Stolen credentials gave attackers entry to Advanced systems. Live tokens then let ransomware move through NHS-linked services with no further logins required.
Hive ransomware followed stolen credentials into Costa Rica's CCSS
Hive ransomware reached Costa Rica's social security agency through the same credential-based entry that Conti had already exploited weeks earlier.
Nelnet Exposed Student Loan Data With No Authentication Barrier
Nelnet disclosed unauthorized access to student loan borrower data affecting millions of records. Public details on the entry method remain limited, but the outcome points to data reachable without ongoing…
Twitter 5.4M Accounts Scraped via API Flaw With No Login Required
Attackers used a Twitter API flaw to pull email addresses and phone numbers from 5.4 million accounts without any user login or token. The vulnerability sat in an endpoint that skipped proper authorization checks.
Costa Rica Conti Attack: Stolen Credentials Then Live Tokens
Conti ransomware reached Costa Rican government systems through stolen credentials. Once inside, attackers operated with live tokens that required no further login at any boundary.
Shutterfly Ransomware: Stolen Credentials Let Attackers Encrypt Without Further Logins
Attackers used compromised credentials to reach Shutterfly systems, exfiltrate customer data, and deploy ransomware with no second authentication step required after entry.
T-Mobile 2021: Brute Force on an Exposed Gateway Stole 76 Million Records
An unprotected GPRS testing gateway accepted brute-force logins with no second factor, giving attackers direct access to customer data systems holding names, SSNs, and addresses.
ShinyHunters Hit Kering: Customer Data Leaked After Credential Access
ShinyHunters accessed Kering systems holding Gucci and Saint Laurent customer records. The entry point aligned with stolen credentials, a vector that left no second factor in place once the first login succeeded.
Cream Finance Lost $130M+ to a Flash Loan No MFA Could Touch
Attackers drained over $130 million from Cream Finance using flash loans that abused smart contract authorization rules. No credentials or login flows were involved.
Robinhood Breach: Social Engineering Gave Direct Access to 7 Million Customer Records
Attackers used social engineering against Robinhood support staff to reach customer data systems holding seven million records, bypassing any second-factor protection on those accounts.
REvil Used Stolen Credentials to Shut Down JBS Plants Worldwide
REvil reached JBS through compromised credentials on remote access systems, moved laterally without fresh logins, and deployed ransomware that halted meat processing across multiple countries.
Kaseya VSA: Zero-Day Auth Bypass Turned MSP Updates Into Ransomware
REvil used a zero-day vulnerability to bypass authentication in Kaseya VSA, push ransomware through trusted MSP updates, and hit over 1,500 organizations downstream.
Facebook Scraped 533 Million Records Through a Broken API Feature
Attackers used a misconfigured Contact Importer feature to pull names, phone numbers, and locations from 533 million accounts with no credentials required.
Colonial Pipeline: Stolen VPN Password With No MFA Shut Down Fuel Supply
DarkSide used a reused password on a dormant VPN account that had never been protected by MFA, then moved through the network to deploy ransomware and force a six-day pipeline shutdown.
SolarWinds: Weak Credentials Opened the Door to Golden SAML Forgery
APT29 reached SolarWinds through password spraying, inserted SUNBURST into Orion updates, then stole SAML signing keys to impersonate users across thousands of victim organizations.
Oldsmar Water Hack: One Weak TeamViewer Password Controlled the Plant
An attacker used a weak shared password on exposed TeamViewer to reach the SCADA operator workstation and tried to raise sodium hydroxide levels before staff noticed.
CNA Financial Paid $40M After Phishing Malware Gave Attackers Free Run
Phishers tricked a CNA employee into running a fake browser update that installed malware, giving attackers network access that led straight to data theft and ransomware.
Tchap Breach: Social Engineering Gave Attackers 73K Accounts Without Cracking a Single Login
Attackers used social engineering to compromise a Tchap user account, exposing France's government messaging platform to potential mass data theft including 650K messages and 13.5GB of files.
Workday Breach: Scattered Spider Impersonated Staff to Steal Account Access
Attackers impersonated IT and HR staff over phone and text to trick Workday employees into surrendering account access, reaching a third-party CRM and customer data.
Lapsus$ Hit Microsoft, Samsung, Ubisoft With One Stolen Credential Set
Lapsus$ used stolen employee credentials and social engineering to reach Microsoft, Samsung, and Ubisoft. Once authenticated, attackers operated with live sessions and tokens that required no further login.
Lapsus$ Nvidia Breach: One Set of Stolen Credentials Exposed Source Code
Lapsus$ reached Nvidia systems with compromised employee credentials, then exfiltrated source code and internal data with no second authentication barrier after the initial login.
Lapsus$ Okta Breach: One Support Call Exposed Customer Tenant Logs
Lapsus$ used social engineering against Okta support staff to reach internal systems holding customer configuration data, bypassing any second-factor check on the accounts they reached.