Gecadi Technology
CybersecuritySeptember 4, 20268 min read

The Phishing Attack That Gets Past Two-Factor Authentication

A fake login page can capture your password and your 2FA code at the same time. Here is what to do in the first ten minutes if you clicked, how the attack works, and what actually stops it.

By Gecadi Technology

A business we work with had two-factor authentication turned on. Every account, no exceptions. One afternoon two of their mailboxes were taken over anyway. By the time the call reached us the attacker had emailed their entire contact list and opened a conversation with their accountant about setting up a payment, and we spent the rest of that afternoon shutting it down.

Two-factor authentication is still worth having. But there is a type of phishing that walks straight through it, and most people have never heard of it. Here is how it works, and what to do if it has already happened to you.

If you just clicked, start here

Do these in order. The second one is the step almost everyone skips, and it is the one that matters most.

1. Change your password. Do it from a device you trust, going to your email provider directly rather than through any link.

2. Sign out of every other session. In Gmail, scroll to the bottom of your inbox, click "Details" next to the last account activity line, and use "Sign out of all other web sessions." In Microsoft 365, your admin can do this from the admin center. This step is critical because the attacker is not using your password. They are using a copy of your logged-in session, and changing your password on its own does not end it.

3. Look for rules the attacker may have left behind. In your email settings, check four places: filters, forwarding, delegated access, and any extra "send mail as" addresses. In the case above, the attacker created a filter that silently deleted every incoming message, so the victim never saw the replies, the warnings, or the security alert from Google. It ran for hours before anyone noticed.

4. Check your deleted items. If a rule like that was running, your mail is not lost. It is in the trash, and it can be restored.

5. Review connected apps and app passwords. In your account security settings, remove anything you do not recognize. App passwords in particular bypass two-factor authentication by design.

6. Tell your IT support and tell your contacts. Everyone in your address book may receive a message from you. The sooner they know it is not from you, the fewer of them get caught.

Do not stop after step one. A password change alone leaves the attacker exactly where they were.

How the attack actually works

The email arrives from someone you know. Not a lookalike address, not a spoof, the real address of a real contact whose own account was taken over last week. It says they have shared a document with you, and there is a button to view it.

The page you land on is not a copy of your email provider's login screen. It is a live relay. The attacker's server loads the real login page and shows it to you, so everything looks correct because everything is correct. Then:

  • You type your email address and password. The server passes them to your real provider.
  • Your provider asks for the 2FA code. The page shows you that prompt.
  • You enter the code. The server passes that along too.
  • Your provider approves the login and issues a session, the same thing that keeps you logged in for weeks without signing in again.
  • That session passes back through the attacker's server, which keeps a copy.
  • You get redirected to your real inbox, and nothing looks wrong.

The attacker now has a working session on your account. They never needed your password again, and they will never be asked for a 2FA code, because from your provider's point of view they are you, already signed in.

This is why the usual advice to "check the sender" does not help here. The sender was genuine. And it is why the attack works the same whether you tapped the link in a mail app on your phone or in a browser on your desktop. Nothing was stolen from your device. The session was created during the login you performed on the fake page.

What happens after they are in

Getting into the mailbox is not the goal. It is the starting point.

What follows is automated, and it begins by reading. The sent folder is the useful half, because it holds how you write, who you write to, and what you discuss with each of them. Out of that comes a short list of the people who have handled money with you before, and among them the one who can actually move it.

Then it writes to that person, as you, about the thing the two of you already do together. In the case above, the message was an ordinary administrative question about how to pay a new contractor. No urgency, no threat, no deadline, no clumsy phrasing. A routine question of the kind that gets answered in a minute without anybody thinking twice about it.

That is why the usual advice runs out here. There is nothing misspelled to notice, no pressure to resist, and no address to check, because the message really is coming from the account it appears to come from.

What this does and does not mean about 2FA

It does not mean two-factor authentication is pointless. It stops the far more common attacks: reused passwords, credentials from an old breach, someone guessing their way in. Every business should still have it turned on.

What it means is that 2FA is not the finish line. It raises the cost of an attack, and this technique is what attackers built to answer it.

The signs, when the sender looks legitimate

Because you cannot rely on the sender's address, you have to watch the request instead.

A login prompt that appears where it should not. This is the strongest signal there is. If you are already signed in to your email and a document link asks you to sign in to your email again, stop. Real document sharing does not work that way. The page in the case above told people to log in to their email for security reasons. That sentence is the attack.

A vague document with no context. Someone you work with usually says what they are sending and why. A bare "I have shared a document with you" from a real contact, with no case name, no invoice number, and no reason, deserves a phone call before a click.

The address bar after the click. Look at the domain before typing anything. These pages are almost always hosted on a legitimate website that was broken into, so the name will be a real business, just not your email provider.

Any request about payments, banking details, or account changes. Confirm it by phone, using a number you already have, not one from the email. This is the part that costs money.

What actually stops it

Passkeys. A passkey is tied to the real website's address. On a fake page it simply does not work, because there is nothing for the user to type and nothing for the attacker to relay. This is the only defense on this list that breaks the attack rather than slowing it down.

A password manager. It fills your credentials based on the site's actual address. On a page that is not your email provider, it stays quiet. That silence, when you expected it to fill, is a warning worth listening to. Here is how password managers work.

Turning off automatic forwarding across your organization. Most businesses never use it, and it is one of the first things an attacker sets up.

Someone watching the security alerts. Google Workspace and Microsoft 365 both flag suspicious sign-ins and user-reported phishing. In the case above, those alerts had been arriving for months with nobody assigned to read them.

Telling your team that reporting a click is safe. The damage in these incidents comes from the delay, not the click. People hide mistakes when they expect to be blamed, and every minute of silence is a minute the attacker spends reading your mail.

The part worth remembering

The business in this case was not careless. They had 2FA on, they caught it, and they picked up the phone before any money moved. That is why this was a bad afternoon instead of a serious loss.

The attack reached them because it came from a trusted contact who had been compromised first. That is the part no filter catches and no policy prevents. What you can control is how fast you react and how much the attacker can do once they are in.

If this has happened to you

If you think one of your accounts has been taken over, the first hour matters more than anything you do afterward. Get in touch with us and we will work through it with you: closing the access, finding what was left behind, and figuring out who needs to be told.

Ready to solve your tech problems?

Talk to a real expert now. We'll get your devices, networks, and servers back on track.