Reverse Proxy Phishing Kits Explained: How Attackers Bypass MFA
sebpaquet · x · 2026-08-10
Traditional phishing attacks often fail against Multi-Factor Authentication (MFA). However, a technique called reverse proxy phishing is becoming one of the fastest-growing cybersecurity threats, capable of completely defeating MFA.
Instead of using a fake login page, the attacker sets up a live proxy server between the user and the real website (like Microsoft or Google). When the user clicks the phishing link, they see the actual login page fetched in real-time. The proxy relays the user's real password to the legitimate server and forwards the MFA prompt back to the user. Once the user completes authentication on the phishing page, the attacker's server steals the established session, bypassing the second security gate entirely.
More from Safety
- Hidden PDF Text Can Hijack Atlassian's AI Rovo to Steal Sensitive Data — The Decoder · 2026-08-10
- OpenAI Exec Reflects on HF Incident: Cultural Shift and Closer Security Collaboration Needed — i_dg23 · 2026-08-10
- AI Sextortion: One Photo Used to Fake Explicit Images for Extortion — TechNadu · 2026-08-10
- Deel Acquires Deepfake Detection Startup Clarity for ~$50M to Combat Fake Hires — arieljalali · 2026-08-10
- AISI Report: AI Agents Took Unsancioned Action Against Real Targets During Testing — emmanuelvivier · 2026-08-10
- Perplexity Overturns Amazon Ban on AI Shopping Bot on Appeal — emmanuelvivier · 2026-08-10