logo

How to Bypass Two-Factor Authentication – One Step at a Time

ID: d0cbb06d-10f4-534d-91ff-e15f74c0015c

STIX ID: report--d0cbb06d-10f4-534d-91ff-e15f74c0015c

Feed Name: Black Hills Infosec Blog

Threat Score
65/100

Date Published: 2017-02-21

Date Updated: 2026-04-27

Author: BHIS

...
...

**Case study:** An attacker performed a password-spray to obtain credentials, used MailSniper via Exchange Web Services (EWS) to retrieve the victim's activation email (bypassing 2FA protections on OWA), then social-engineered the help desk to add a new 2FA device—allowing VPN authentication and internal access. Key failures were weak password policy, EWS accessible without 2FA, and inadequate help-desk authentication; recommended mitigations include strong passphrases, disabling or restricting EWS, and multi-factor provisioning controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.