Phishing and MFA Exploitation: Targeting the Keys to the Kingdom
In 2025, cyber attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows and leveraged compromised credentials for sophisticated phishing campaigns. According to Cisco Talos, phishing remained a primary initial access vector, accounting for 40% of incidents. Attackers shifted from generic spam to workflow-style emails mimicking IT, travel, and logistics tasks, often abusing Microsoft 365 Direct Send to spoof internal communications and bypass security filters. A significant trend involved cascaded phishing, where trusted accounts were used to target partners and third parties. Simultaneously, identity and access management (IAM) systems became major targets, with nearly one-third of MFA spray attacks focusing on these platforms. Device compromise surged by 178%, driven largely by voice phishing tricks aimed at administrators. The higher education sector was particularly vulnerable to device compromises due to diverse, unmanaged device populations and lower verification policies. These trends highlight a strategic shift by adversaries to exploit trust in everyday business operations and authentication mechanisms, turning security tools into points of failure.
Wire timeline
Phishing and MFA Exploitation: Targeting the Keys to the Kingdom
In 2025, cyber attackers increasingly targeted weaknesses in multi-factor authentication (MFA) workflows and leveraged compromised credentials for sophisticated phishing campaigns. According to Cisco Talos, phishing remained a primary initial access vector, accounting for 40% of incidents. Attackers shifted from generic spam to workflow-style emails mimicking IT, travel, and logistics tasks, often abusing Microsoft 365 Direct Send to spoof internal communications and bypass security filters. A significant trend involved cascaded phishing, where trusted accounts were used to target partners and third parties. Simultaneously, identity and access management (IAM) systems became major targets, with nearly one-third of MFA spray attacks focusing on these platforms. Device compromise surged by 178%, driven largely by voice phishing tricks aimed at administrators. The higher education sector was particularly vulnerable to device compromises due to diverse, unmanaged device populations and lower verification policies. These trends highlight a strategic shift by adversaries to exploit trust in everyday business operations and authentication mechanisms, turning security tools into points of failure.
Cisco Talos Blog