Top 2026 2FA & AiTM Detection: Multiple Failed MFA Then Single Success From Diff
Detects a suspicious authentication pattern involving 3 or more MFA failures within 15 minutes, immediately followed by an MFA success for the same user. This pattern is characteristic of potential Adversary-in-the-Middle (AiTM) activity, where an attacker intercepts a session or MFA token and relays it through separate infrastructure, while the legitimate user's own MFA attempts fail or time out.
Sigma

