They Had MFA. The Attacker Logged In Anyway.

They Had MFA. The Attacker Logged In Anyway.

An operations director at a Bangkok SME approved an MFA prompt in the back of a taxi. Eleven days later, two employees couldn't log in, 1.8 million baht had gone to the wrong bank account, and a 72-hour legal clock nobody knew about had started running. Here's exactly how the attack worked, what the company got wrong in the first hour, and the five configuration changes that would have stopped it.

Read More