Knowbe4 iconKnowbe4Jul 23, 2026

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

The first tool, called "Jalisco," is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time. Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA).

New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication

Share this story

Send the public story page.

Useful takeaways from this story.

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA).

The first tool, called "Jalisco," is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

Researchers at ReliaQuest are tracking two new phishing toolkits that are designed to bypass multifactor authentication (MFA). The first tool, called "Jalisco," is a device code phishing platform that pairs with AI-powered phishing-as-a-service platforms like EvilTokens to provide fresh OAuth codes in real time.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app