Top 2026 2FA & AiTM Detection: Phishing-Resistant MFA Downgrade Attempt

Detects sign-in activity where an attacker or user fails a phishing-resistant MFA challenge (such as FIDO2, Windows Hello, or Passwordless Phone) and immediately succeeds using a lower-assurance, phishable factor (SMS, Voice call, or Push notification). This pattern is indicative of an Adversary-in-the-Middle (AiTM) attack attempting to bypass stronger authentication methods.