Modern Phishing & Social Engineering
Phishing stopped being about bad spelling and fake lottery wins years ago. Today's operators run polished pretexts, wear down defenders with MFA-fatigue, and use adversary-in-the-middle proxies that steal live session tokens — walking straight past multi-factor authentication. Understanding the modern kill chain is the first step to defending against it.
Social engineering endures because it targets the one component you cannot patch: human judgement under pressure. What has changed is the sophistication of the machinery around that human. The industry once reassured itself that multi-factor authentication (MFA) had solved credential phishing; adversary-in-the-middle techniques have quietly made much of that reassurance obsolete. This article walks the modern phishing kill chain and, at each step, names the layered control that blunts it. Guidance from CISA underpins much of the defensive advice here.
Pretexting — the human setup
Every effective social-engineering attack begins with a pretext: a believable story that gives the target a reason to act. A finance clerk receives an urgent invoice from a known supplier; an employee gets a calendar notice about a mandatory security update; a help-desk agent is called by a panicked "executive" locked out before a board meeting. Modern pretexts are researched from public sources — org charts, social media, press releases — and increasingly polished with generative AI, which has stripped away the grammar mistakes that once gave phishing away.
Why authority and urgency work
Pretexts lean on predictable psychological levers: authority, urgency, scarcity, and the desire to be helpful. Naming these levers in awareness training is more durable than teaching staff to spot specific scams, because the levers do not change even as the stories do.
MFA fatigue — exhausting the human
Once an attacker has a valid password (from a breach dump, reuse, or an earlier phish), some MFA implementations become the weak point. In an MFA-fatigue attack, the adversary triggers a flood of push notifications, betting the victim will eventually approve one out of annoyance or confusion. The countermeasure is straightforward and effective: replace simple approve/deny push with number matching, cap repeated prompts, and alert on bursts of denied MFA requests, which are a reliable indicator of an attack in progress.
The moment a login prompt appears out of nowhere, the correct action is suspicion, not approval. A push you did not initiate is an alert, not an inconvenience.
Adversary-in-the-middle — defeating MFA
The most consequential shift in phishing is adversary-in-the-middle (AiTM). Rather than harvest a static password, the attacker stands up a reverse proxy between the victim and the real login page. The victim sees a pixel-perfect portal, enters their credentials, and completes the genuine MFA challenge — because the proxy is relaying every step to the real service in real time. The prize is not the password but the session token the service issues afterward. With that token, the attacker resumes an already-authenticated session and never has to satisfy MFA again.
This is why "we have MFA" is no longer a complete answer. Traditional one-time codes and push approvals are phishable precisely because they can be relayed through the proxy along with everything else.
The control that actually breaks AiTM
The decisive defence is phishing-resistant MFA — FIDO2 security keys and passkeys built on WebAuthn. These bind the authentication cryptographically to the legitimate site's origin, so a credential presented to an attacker's proxy domain simply will not verify. There is no code for the victim to read out and no approval to relay; the browser and authenticator refuse to authenticate to the wrong origin. CISA and other authorities now explicitly recommend phishing-resistant MFA for exactly this reason.
Layered defence — the stack, not the silver bullet
No single control catches every step, so defence is deliberately layered along the kill chain shown in Figure 1:
- Email authentication — SPF, DKIM, and a DMARC policy set to reject, plus modern filtering, stop a large share of lures before they land.
- Awareness and easy reporting — a trained workforce with a one-click "report phish" button turns every employee into a sensor.
- Phishing-resistant MFA — FIDO2 and passkeys neutralise credential and token theft at the authentication step.
- Conditional access — device-compliance, location, and risk signals block logins that do not fit the user's normal pattern even if a token is stolen.
- Session monitoring — detecting impossible travel, anomalous token use, and unfamiliar sign-in properties catches takeover after the fact and shortens dwell time.
Each layer assumes the ones before it may fail. That assumption is the whole philosophy of defence in depth: an attacker who slips past filtering still faces phishing-resistant MFA, and one who somehow obtains a token still faces conditional access and session analytics.
Testing the human layer safely
Finally, the human layer deserves the same rigour as the technical one. Authorised social-engineering assessments — run ethically, with care for staff wellbeing and clear rules of engagement — reveal where pretexts land and where reporting breaks down, and they measure whether awareness training is actually changing behaviour. The goal is never to shame employees but to strengthen the organisation's collective reflexes before a real adversary tests them.
Key takeaways
- Modern phishing relies on pretexting, exploiting authority and urgency rather than obvious tells.
- MFA fatigue is defeated by number matching, prompt caps, and alerting on denied-request bursts.
- Adversary-in-the-middle steals live session tokens and walks past traditional MFA.
- Phishing-resistant MFA (FIDO2 / passkeys) is the control that actually breaks AiTM, by binding auth to origin.
- Defence is a layered stack — email auth, awareness, phishing-resistant MFA, conditional access, and session monitoring.