“But I’ve Got MFA – I’m Safe”

Posted: September 1, 2026Category:

“But I’ve got MFA – I’m safe.” I hear that a lot. Here’s the bit that catches people out.

You don’t need your password stolen to get hacked.

You click a link that looks legit, sign in like you always do – and in the background they grab your session cookie. That’s the little pass your browser holds that says “this person’s already logged in.”

With that cookie they don’t need your password. They don’t need your MFA (multi-factor authentication) code either. They’re just in – as you.

No alarm. Nothing looks wrong.

So what’s the real question?

It isn’t “have I got MFA”.

It’s “if someone slips past it, who’s watching to kick them back out?”

That’s the bit most small businesses are missing. Something watching for the dodgy login & shutting it down before any damage is done.

We use Huntress ITDR (identity threat detection & response) for exactly this. It has caught this attack on a client and had it sorted in minutes – the customer had no idea anything had happened until we called.

Got MFA but nothing watching behind it?

That’s the gap. Happy to take a quick no-jargon look.

Give us a ring on 09 222 7770, or take the free 2-minute cyber readiness check and see where you stand.

Contact us today