account compromise: what businesses should know
account compromise is an important part of keeping business technology practical, secure and reliable. This article explains the issue in plain language, with related context on publicly shared information and useful external guidance on multi-factor authentication.
For a long time, the advice has been simple: turn on
Multi-Factor Authentication (MFA) and you’re safe.
That advice is not wrong.
It’s incomplete.
MFA is one of the strongest security controls available. When it’s configured properly and actively monitored, it stops the majority of account takeovers. Every business should be using it.
Where businesses get caught out is treating MFA as a checkbox. Enabled once, never revisited, never tested against how attacks actually happen.
That gap is where most compromises occur.
How accounts are really compromised
Most people still imagine hacking as something highly technical.
In reality, most compromises are human-driven.
Common patterns look like this:
- A SIM swap redirects OTPs to an attacker
- A WhatsApp account is taken over and used for impersonation
- A user approves repeated login prompts out of frustration
- A phishing page captures a valid session after MFA
- A recovery email is compromised and used to reset everything
In almost every case, MFA was enabled.
The issue was not MFA itself, but the lack of context and control around it.
SIM swaps are identity fraud
A SIM swap is not hacking. It’s impersonation.
Attackers collect personal information first. Names, phone numbers, ID numbers, employers, addresses, travel plans. Much of this is publicly available or pulled from historic data leaks.
They then contact the mobile provider and claim the phone was lost or stolen. Sometimes there’s bribery involved. More often, it’s just confidence and a believable story.
Once the number is moved, the real phone loses signal and verification codes start going to the attacker.
Any system relying on SMS alone is now exposed.
That’s not MFA failing. That’s a weak delivery method being used.
Why WhatsApp is often next
WhatsApp is tied to phone numbers. Once the number is controlled, activating WhatsApp on a new device is straightforward.
The code is sent.
The attacker receives it.
The legitimate user is logged out.
WhatsApp is now used for more than messaging. OTPs, recovery messages, alerts. Once WhatsApp is compromised, other accounts often follow.
WhatsApp does provide protection in the form of a
registration PIN. When enabled, WhatsApp cannot be activated on a new device without that PIN, even if the SMS code is intercepted.
It’s simple.
It works.
It should always be enabled.
Public information makes impersonation easier than people realise
Strong authentication assumes attackers cannot convincingly pretend to be you.
That assumption fails when too much information is publicly visible.
Attackers don’t guess. They assemble profiles. Professional pages, social media, old leaks, small details that seem harmless on their own.
Together, they make impersonation easy.
Locking down social profiles, removing public contact details, and thinking twice before sharing travel plans materially reduces risk. For administrators and senior staff, this matters even more.
Malware breaks trust at the device level
MFA assumes the device being used is trustworthy.
Malware breaks that assumption.
Most infections don’t come from advanced exploits. They come from behaviour. Cracked software, unofficial extensions, unsafe downloads, links people know they shouldn’t click.
Modern malware is quiet. It captures credentials and session tokens in the background. MFA can be working perfectly while access is being handed over silently.
That’s not MFA failing.
That’s the endpoint being compromised.
Private browsing does not make risky behaviour safe
Private or incognito browsing is widely misunderstood.
It mainly prevents local history from being saved.
It does not make activity anonymous or secure.
Your ISP can still see traffic.
Websites still see you.
Malware still sees everything.
Believing otherwise leads people to take risks they normally wouldn’t. Attackers rely on that false sense of safety.
Phishing and fake support calls still do most of the damage
A large number of compromises start with a click or a call.
Phishing pages today are extremely convincing. If you’re asked to log in or submit information, ask one question:
Did I intentionally go to this site myself?
If not, stop.
Phone-based social engineering is just as common. Fake support calls asking you to “confirm” information they should already have. Pressure. Urgency. Authority.
Reputable organisations will never ask for passwords, PINs, or one-time codes over the phone. They will never object if you say you want to verify the request independently.
If a call feels off, hang up.
Most phones record calls. If something goes wrong, keep the recording. It can be critical evidence.
What a real solution actually looks like
This is where configuration matters.
Proper
identity protection is not just MFA. It’s
context-aware access control.
In platforms like
Microsoft 365 Business Premium, MFA is combined with:
- Geo-based access restrictions
- Risk-based sign-in detection
- Device compliance checks
- Stronger authentication when behaviour changes
This allows access to be blocked from high-risk regions, tightened for sensitive accounts, and temporarily adjusted when staff travel.
Instead of simply asking, “Do you have the password and the code?”, the system asks, “Does this login make sense?”
That is how MFA is meant to be used.
The bottom line
MFA works.
But it is not fire-and-forget.
The businesses that get compromised are not the ones using MFA.
They’re the ones assuming MFA alone is enough.
Security starts long before the login screen.
But when you reach it, MFA, correctly configured and actively monitored, is still one of the best defences you can have.
0 Comments