May 27, 2026

The attack dominating financial services doesn't steal passwords. It resets MFA and steals the token.

Illuminated cityscape at night reflecting on calm water
Thilina Alagiyawanna / Unsplash

The attacker who hit the most financial services organizations over the past 12 months never phished a password. They called an IT support line, convinced an employee to reset their MFA, and registered their own device on the network.CrowdStrike’s 20...