Is MFA enough to stop phishing without staff training?

MFA cuts account compromise risk by 99.22% (Microsoft research), yet relay kits, push bombing and voice phishing still get through. What staff training adds in 2026.

No, MFA alone is not enough to stop phishing in 2026. Microsoft's own research measured a 99.22% reduction in account compromise risk from MFA, which is why it should be switched on everywhere — but the phishing attacks that now reach inboxes are built for MFA-protected accounts. Adversary-in-the-middle relay pages steal live session tokens, MFA fatigue attacks flood staff with approval prompts, and voice phishing talks employees into handing over codes. MFA removes the easy attacks; staff training removes the humans the remaining attacks depend on.

TL;DR

Is MFA enough to stop phishing without staff training?

No — MFA is necessary, but it is not sufficient. MFA is the highest-impact technical control you can switch on, and the answer to whether it stops phishing on its own is still no, because modern campaigns target the session, the approval prompt and the person rather than the password. The realistic 2026 setup pairs MFA on every internet-facing service with training that covers the specific techniques built to defeat it.

The split of work looks like this:

Phishing techniqueWhat MFA does against itWhat covers the gap
Credential harvesting pageThe stolen password alone is useless — the attacker still needs your second factorStaff spotting the lookalike domain before they type
Adversary-in-the-middle relayBypassed — the relay proxies a live, MFA-valid sessionStaff checking the domain on any emailed or chatted sign-in
MFA fatigue (push bombing)Sends approval prompts to the real user — one tap ends itStaff denying and reporting prompts they did not trigger
Voice phishing for codesBypassed — the employee reads the one-time code aloudStaff refusing to share codes with anyone, ever
Consent phishing (OAuth app)Not involved — the attack rides an approval the user grantedStaff declining unexpected app-consent screens

Microsoft's MFA research paper reports that 99.99% of MFA-enabled accounts stayed uncompromised during its study period, with compromise risk down 99.22% across the population and 98.56% in the leaked-credentials case (Microsoft MFA research paper). Those numbers are the strongest argument for deploying MFA this quarter. They are also the reason attackers moved downstream: what survives MFA is precisely the class of attack that does not fight the second factor — it persuades the human to hand it over.

What the breach data says in 2026

Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches and found the human element involved in about 60% of them (Verizon 2025 DBIR). That share has held near 60% for years, through spam filters, secure email gateways and a decade of MFA rollouts. The tools moved; the human share did not.

Sophos' State of Ransomware 2025 survey adds the credential angle: compromised credentials were cited as the root cause in 23% of ransomware attacks, second only to exploited vulnerabilities at 32%. Credentials get phished. Even at organisations running MFA, the people-side entry point stays open until the people are trained.

Two planning conclusions follow:

The three techniques that defeat MFA — and the reflexes to train

1. Adversary-in-the-middle relay pages

A relay kit proxies the real login page. Staff type their credentials into what looks like the normal Microsoft 365 sign-in, the page forwards everything — password, MFA approval and all — to the genuine service, and hands the attacker a live session cookie. From the employee's side nothing looked wrong, because the MFA prompt they approved was real.

The trainable reflex is the source check: treat any sign-in link that arrives by email, chat or SMS as hostile until the domain checks out. The guide to spotting fake Microsoft 365 login pages walks through the six-second check staff can run before they type.

2. MFA fatigue and push bombing

Push bombing fires approval prompt after approval prompt at the real user, sometimes paired with an "IT here, please approve, we're updating systems" message, until a busy employee taps Approve to make the noise stop. Number matching — where the authenticator app shows a number the user must type — raises the technical bar, but the durable fix is behavioural: staff should treat an unexpected prompt as an attack signal, deny it and report it.

The guide to recognising MFA push bombing attacks covers the exact reflex and the reporting script to drill.

3. Voice phishing and help-desk social engineering

The third technique skips links altogether. An attacker phones an employee — or calls your help desk impersonating one — and talks their way past MFA: a password reset, a one-time code read aloud, or an MFA device re-registration. No mail filter sees that call and no MFA configuration blocks it. Only a rehearsed verification procedure — call back on a known number, never accept an inbound reset — does.

What training adds that MFA cannot

MFA is a gate at sign-in. Phishing in 2026 happens everywhere else: chat, SMS, phone calls, shared files and app-consent screens — several of which never pass through your mail gateway. Training is the control that follows the person:

How to layer MFA and training in 2026

  1. Switch MFA on everywhere, with number matching wherever your platform supports it.
  2. Teach the three exception techniques — relay pages, push bombing and voice phishing — in short monthly sessions rather than one annual lecture.
  3. Simulate the reflexes. Phishing simulations test staff monthly; anyone who fails is auto-enrolled into remediation training instead of receiving a quiet email.
  4. Track two numbers. Click rate measures exposure; report rate measures detection. Both should trend the right way quarter over quarter.
  5. Escalate difficulty as report rates climb, so the programme keeps pace with attacker techniques.

Awareness training built around a monthly cadence keeps steps 2 and 3 running continuously — the only cadence that matches techniques that change month to month.

Is MFA still worth deploying without training?

Yes. The 99.22% risk reduction holds whether or not staff are trained, and it removes the bulk of automated credential attacks on day one. Deploy it immediately; treat training as the control that covers what it cannot.

Can phishing bypass MFA?

Yes — through adversary-in-the-middle relay kits, prompt-bombing approvals and socially engineered resets. These bypass the technology by operating through the person, which is why the fix has to be human as well as technical.

What should staff be trained on alongside MFA?

Three reflexes: verify any sign-in link's domain, deny and report unexpected MFA prompts, and never share one-time codes or approve requests made over the phone. Each takes minutes to teach and fails without repetition.

FAQ

Is MFA enough to stop phishing by itself in 2026? No. MFA reduced compromise risk by 99.22% in Microsoft's research, but adversary-in-the-middle kits, push bombing and voice phishing are designed to defeat or route around it. Training covers those gaps.

Does MFA reduce phishing risk for leaked credentials? Yes. Microsoft measured a 98.56% reduction in compromise risk for leaked credentials when MFA was enabled, which is why credential-harvesting phishes lose most of their value.

What share of breaches still involve people? About 60% of breaches involve the human element, per Verizon's 2025 DBIR — a share that has held steady despite widespread MFA adoption.

Does number matching stop push bombing? It stops blind tapping by requiring the number shown on screen, but a distracted or socially engineered employee can still approve. Training on denying and reporting unexpected prompts remains necessary.

How often should staff be trained on MFA-related phishing? Monthly short modules with periodic simulations. An annual session decays long before attacker techniques change monthly.

Should we postpone training until MFA is fully rolled out? No. Run both in parallel — MFA cuts automated attacks immediately while training builds the reflexes for the attacks MFA leaves behind.

One last thing

Watch your report rate, not just your click rate. Click rate tells you how many people took the bait; report rate tells you how many would raise the alarm on a real one. A team that clicks less but reports nothing is still blind — and the attacks that survive MFA are exactly the ones a fast report cuts short.

Related guides

Ready to deploy

Same playbook.
Your brand.

Cyber Aware's Human Risk Score works the same way for every MSP partner - under your brand, on your cadence.