19 documented legacy MFA failures — and counting.

Legacy MFA Hall of Shame

It got phished or bypassed.
Again.

A running record of every breach where SMS codes, OTP apps, and push notifications got bypassed, stolen, or simply ignored. No spin. Just receipts.

The Breach Log

Spring Ring Teams vishing never stole MFA codes
Unit 42’s Spring Ring used fake Teams IT helpdesks and 10–15 minute calls to push RMM or malware on 150+ staff. No passwords or MFA codes taken at login.
BigBear 2.0 Evilginx2 stole M365 cookies after MFA
CloudSEK found BigBear 2.0's Evilginx2 PhaaS proxied live M365 logins, captured MFA, and exfiltrated 4,148 session cookies across 258 orgs.
AdaptHealth contractor SE exposed 4.1M patients
Social engineering compromised a privileged AdaptHealth contractor session. Attackers used identity-plane cloud access to expose about 4.1 million patients. No malware reported.
Aesto Health 9.5M breach has no public vector
Aesto Health’s disclosure wave cites over 9.5 million patients. Public reporting does not establish how attackers got in, what identity was abused, or any MFA path.
Passkey helpdesk vishing stole Entra M365 sessions
Microsoft tracked helpdesk callers since May 2026 who steered Entra users into passkey-themed AiTM and device-code flows, then stole sessions and enrolled attacker MFA.
Midnight Blizzard device-code phishing stole M365 tokens
GTG-20006 tricked staff into real Entra MFA on login.microsoftonline.com, then took OAuth tokens and bulk-exported Microsoft 365 mail from at least eight orgs.
GhostCode stole OAuth tokens after real Microsoft MFA
GhostCode never stole a password. Victims finished real Microsoft MFA, then attackers collected OAuth tokens, registered devices, and harvested email within seconds.
N0va kit: real MFA, stolen Microsoft tokens
N0va tricks workers into real Microsoft MFA on a device-code flow, then walks off with access and refresh tokens plus PRT-style device persistence. No password harvest required.
IEH M365 mailbox phished via fake login page
IEH’s 8-K: one employee typed M365 credentials on a fake login page after a spoofed document-share lure. Single mailbox access, malicious rules, no confirmed exfil.
Gunra Fortinet VPN and VDI OTP backdoor TTPs
Gunra affiliates combined Fortinet auth-bypass CVEs, VDI session-cookie theft, and a server-side OTP backdoor. CISA AA26-222A maps the workforce identity failures.
DGFiP Breach: Usurped Agent and Third-Party Logins Exposed Tax Data on 678,000
ZeroBytes abused usurped DGFiP agent and third-party logins, claimed an MFA bypass, and pulled tax and cadastral data on 678,000 before access was cut.
TheHatman Lists 3.64M Entra Employee Dumps; TCS Filing Names Password Spray and Push Fatigue
TheHatman advertised ~3.64M Azure/Entra employee records from nine firms. Only TCS’s filing names password spray and push MFA fatigue; TCS and Gap dispute a fresh breach.
UNC6671 vishing stole hedge fund MFA sessions
UNC6671 spoofed helpdesk numbers, guided hedge fund staff to AiTM sites, and stole live MFA plus M365/Okta SSO sessions for multi-brand cloud extortion.
Five-week vishing harvested MFA codes at 200+ orgs
A five-week vishing campaign built phishing infrastructure against 200+ organizations, pushing employees onto spoofed logins that harvested passwords and MFA codes.
Mirage2FA AiTM stole M365 MFA and session cookies
Mirage2FA (LinXcoded) proxied Microsoft 365 logins, relayed live MFA, and stole session cookies. ANY.RUN tracked thousands of potential enterprise compromises.
Payroll Pirates: users finished MFA, sessions stolen
Voicemail lures proxied real Microsoft 365 login. Users finished MFA; attackers harvested session cookies and hunted payroll mail across hundreds of orgs.
AiTM stole a live Microsoft 365 session for BEC
One HR-themed click fed password and MFA through an AiTM proxy. Attackers replayed the Microsoft 365 cookie for ~30 days of cloud-only payment diversion.
Weak email password opened Bank of Baroda file theft
TripleX claimed 700GB–1TB from Bank of Baroda after one employee email password failed. The bank said core banking stayed untouched; mail files did not.
Greatness PhaaS stole MFA-approved Microsoft 365 tokens
Greatness PhaaS used RingCentral-spoofed AiTM and device-code lures to capture MFA-approved Microsoft 365 tokens, then replayed them across M365 apps for weeks.