A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?

Oct 2, 2026Incognito CyberSecurity

A Stolen Login Gets Handed Off in 22 Seconds: Is Your MFA Strong Enough?

🇲🇽 Leer en Español →

Picture this: an employee’s password leaks on a Tuesday. By the time you finish your coffee, a different criminal gang already owns the keys to your email. Not days later. Seconds later. That is the world small businesses are working in right now, and October, Cybersecurity Awareness Month, is a good time to look at it honestly.

Infographic: three habits that shut the door on stolen logins - phishing-resistant MFA, guard five risky actions, audit your AI tools

Hackers do not break in anymore. They log in.

A recent Forbes piece on small business security pulled together some numbers that stuck with me. Google’s Mandiant team found that the time between an attacker getting initial access and handing it to a second criminal group dropped to just 22 seconds in 2025. In 2022, that handoff took about eight hours. Think of it like a relay race where the baton is your stolen password, and the runners have gotten very, very fast.

The same article cites Verizon’s 2026 data: 96% of ransomware victims are small and midsize businesses, and in 38% of those cases the attackers had compromised credentials. In plain English, they did not smash a window. They used a key.

Why your current MFA might not be enough

You probably already use multi-factor authentication, or MFA: the text code or the “Approve this sign-in?” tap on your phone. Good. Keep it. The Forbes article notes that modern MFA cuts the risk of identity compromise by more than 99%. But “modern” is the key word. Criminals have learned to work around the weak versions:

  • Push bombing: they spam your employee with approval requests at 11 p.m. until one tired thumb taps “Approve.”
  • Fake login pages: the employee types the password and the code into a convincing copy of the real site, and the criminal uses both instantly. I covered a version of this in my post on device-code phishing.
  • Text-message codes: these can be tricked out of people or intercepted.

The stronger option is called phishing-resistant MFA: passkeys or physical security keys. They only work on the real website, so there is nothing for a fake page to steal. It is the difference between a code someone can read over your shoulder and a key that only fits one lock.

Protect the moments that matter most

You cannot watch every click your team makes, and you should not try. Instead, the article suggests picking a short list of actions where a stranger doing them would cost you real money. For most small offices that list looks like this:

  • Changing a password or recovery email
  • Adding a new administrator
  • Exporting your client list
  • Changing payment or bank details
  • Creating forwarding rules on a mailbox

For those five, ask for an extra check, such as a fresh sign-in or a call-back to a known phone number, instead of nagging people about every little thing. Too many prompts and people learn to click through them all.

Do not forget your AI tools

Many businesses added AI assistants this year, and some of those tools act inside logged-in sessions: reading email, opening files, filling in forms. The article’s advice is blunt. Review every AI tool you have turned on, and ask each vendor what it can do inside a signed-in session and who else can reach it. If nobody can answer, that is your answer.

What you can do this week

  1. Turn on MFA everywhere. Start with email, banking, payroll, and your accounting software.
  2. Switch your owner and admin accounts to passkeys or security keys. Those are the accounts criminals want most.
  3. Turn on number matching if your app offers it, so a blind “Approve” tap does not work.
  4. Write down your five risky actions and decide what extra check each one needs.
  5. List your AI tools and ask vendors who can see inside a signed-in session.
  6. Tighten your email defenses. Good spam and virus filtering stops many credential-stealing emails before anyone sees them.
  7. Train your team in 15 minutes. Our cybersecurity awareness training teaches people to report an odd approval request instead of tapping it.

The bottom line

You cannot stop every password from leaking. You can make a stolen password useless. Strong MFA, a short list of guarded actions, and a few honest questions to your software vendors will do more than any fancy monitoring tool. If you want help sorting out where you stand, our small business cyber security solutions and endpoint protection cover this, and you can find more plain-English tips on our blog.

Not sure how strong your logins really are?

We will review how your team signs in, find the weak spots, and give you a simple plan to fix them. No pressure, no jargon.

Book a complimentary visit

Send us a message

ICS Form

🔒 This form is protected by spam filtering. Your information is only used to respond to your inquiry.

Source: Forbes: Small Business Security Now Depends On What Happens After Login (Mandiant and Verizon figures as cited there).

— Nemuel Cruz, Incognito Cyber Security

About the author
Nemuel Cruz

Nemuel Cruz is the founder and owner of Incognito Cyber Security, a managed IT and cybersecurity provider based in Tucson, Arizona. Since 2011 he has helped small businesses across Southern Arizona secure their systems, support their staff, and keep running with 24/7 emergency response. He writes about security in plain English for owners who have a business to run.

Questions about this article? Email nemuel@incognitocybersecurity.com or book a complimentary visit.

Related

Latest News