CIO Brief: Stolen Tokens Bypass Passwords and MFA — What That Means for You
Retrospective: this article looks back at events from September 2018, written in 2026 with the benefit of hindsight.
The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without passwords. The same kind of theft is now one of the most common ways attackers get into company email and cloud apps.
Why sign-in protection isn't enough anymore
Multi-factor authentication protects the moment someone signs in. After that, the user's device holds a token that keeps them signed in. If an attacker steals that token — through a fake sign-in page that relays the session, or malware on a laptop — they can skip the password and MFA entirely.
The business impact
- Account takeover despite MFA, often leading to invoice fraud and data theft.
- Slow detection, because the attacker's activity looks like a normal signed-in user.
Questions to ask your team
- How long do sign-in sessions last, and are they shorter for administrators and personal devices?
- Can we require that company data only be accessed from managed, compliant devices?
- Would we detect the same session being used from two countries?
- How quickly can we sign a user out of everything?
What good looks like
Shorter sessions for risky situations, access limited to managed devices for sensitive data, alerts for unusual session use, and the ability to revoke all sessions in minutes.
The decision
Ask your team whether your MFA can be bypassed by a phishing kit that steals sessions. If the answer is yes — and for most organizations it is — prioritize device-based access controls and phishing-resistant MFA.
- Facebook's 'View As' Breach (Sept 2018): 50 Million Access Tokens Stolen Incident Teardowns
- How to Configure Token Lifetimes and Sign-In Frequency in Conditional Access How-To & Hardening
- Detecting Access Token Theft: Entra Sign-In Logs and Sentinel KQL Detection & Response