Another good reason to enforce MFA • Blisstech Solutions

What would happen if someone got hold of one of your employees’ passwords from years ago?

Not a password they’re using today.

Not one they even remember.

Just an old one that never got changed.

Because that’s exactly how a recent, large-scale data-theft campaign worked.

A recent investigation by a cyber security firm uncovered a new hacking campaign. Sensitive business data from dozens of organisations around the world was quietly collected and later put up for sale on the dark web.

Different industries. Different countries. Different sizes of business.

But one thing kept coming up again and again.

Every affected organisation had allowed staff to log into important cloud systems using nothing more than a username and password. No second step. No extra check. Just type your password and you’re in.

This is where MFA comes in.

Multi-factor authentication simply means using more than one piece of evidence to prove it’s really you. Usually that’s your password plus something else, like a code on your phone, a notification you approve, or a fingerprint. 

So even if someone steals your password, they still can’t get in.

In these cases, MFA wasn’t enforced.

So how did the attackers get hold of the passwords in the first place?

They relied on something called infostealing malware. That’s a type of malicious software that can end up on a computer without the person using it realising. 

Once it’s there, it quietly collects saved passwords, login details, and other sensitive information, and sends it back to criminals.

This doesn’t only happen on office computers. It can happen on home devices, personal laptops, or any machine that’s ever been used to log into work systems.

When those details are stolen, they don’t always get used straight away. And this is the part that really matters.

Some of the passwords used in this campaign were years old.

That tells us two important things:

  • Passwords weren’t being changed often enough
  • Old logins were still being trusted long after they should have been invalidated

In other words, a device infected a long time ago could suddenly become a serious problem today.

This has been described as a “latency” issue. The threat sits quietly in the background, waiting. An old mistake doesn’t disappear just because time has passed.

The attackers would have been stopped if MFA had been switched on.

They had the passwords. But they didn’t have the second factor. No phone. No app. No approval tap. That one extra step would have turned a successful break-in into a dead end.

This is why security professionals (like me) keep saying the same thing, repeatedly: Passwords on their own are no longer enough.

I know one of the most common reactions to MFA is, “But it’s annoying”. And yes, it does add an extra moment to the login process. 

But compare that to what happens when a password nobody remembers is still valid years later. When confidential files can be copied, sold, or quietly taken without anyone noticing until it’s too late.

MFA turns a stolen password into a useless piece of information. And that’s why enforcing MFA isn’t overkill anymore, it’s sensible.

If there’s one lesson here, it’s a simple one: Old passwords don’t expire on their own. One extra lock on the door makes all the difference.

Need help getting set up? Get in touch.

More Content

Tech Tip: How to Tidy up Copied Data in Excel

This Tuesday Two Minute Tech-tip shows you how to tidy up data in Excel spreadsheets. Do you have data in a messy format and need to change it so it is organised? Have you ever received data in Excel or in a text file or Word document and wanted to change it from rows...
A person in a hoodie surrounded by green cipher text

3 Things You Must Do to Protect Against Ransomware

Ransomware is an increasingly common and devastating cyberattack that can happen to any business. The ransomware attacks that get the most media attention are those on high profile companies, but ransomware attacks on small businesses are increasing too. Many smaller...
Stop AI agents creating security blind spots

Stop AI agents creating security blind spots

AI is starting to do more than just help your team.
It’s making decisions and taking actions on your behalf.
Everything runs and work gets done faster.

But if something doesn’t look right, could you explain why?

Security essentials: How to stop spam before it stops your business

Is your inbox already full of junk before you’ve even had your first coffee? Most people just sigh, delete, and move on. But what if one of those “junk” emails wasn’t just annoying… but dangerous? Spam has evolved. Today it’s one of the easiest ways for cyber...
You’ve heard of Copilot… but what is it?

You’ve heard of Copilot… but what is it?

You might have heard about Microsoft Copilot, but what is it? And will it really make a difference to your workday or business? We explain it all here.

New: You decide what Copilot remembers

New: You decide what Copilot remembers

Microsoft’s latest update is changing the way AI assistants work with your business. And it’s putting you firmly in the driver’s seat. Here’s what that means for you…

Windows 10 is getting a very useful Windows 11 feature

Windows 10 is getting a very useful Windows 11 feature

There’s no denying that Windows 11 has a lot of really cool new features. If you haven’t made the move from Windows 10 yet, you’re missing out. But there’s good news. To make the (eventual) move from Windows 10 to 11 a little easier, Microsoft is sharing a couple of...
And the award for most common phishing scam goes to…

And the award for most common phishing scam goes to…

Which phishing scam are you and your employees most at risk from? We tell you about the most common phishing emails and the easy way to stay safe.

8 tech trends you need to prepare for in 2023

The end of the year is a time when many business owners take time to reflect and plan for the coming year. For many that will involve thinking about forecasting and growth over the next 12 months, but we want you to think about the tech trends in 2023 that will affect...

Tech Tip: How to add an email alias as FROM address in Outlook

You've been using Microsoft Outlook for a while now and you're comfortable with the interface. But there's one thing you still haven't figured out how to do- send an email from an alias address. Microsoft 365 has made it possible to easily add a new FROM address in...
Share This
Contact
Love Lane
Cleobury Mortimer
Shropshire DY14 8PE

01299 382 321
[email protected]
Copyright © Blisstech Solution Ltd
Registered No: 08125391 VAT No : 307 5490 05