Desk live·
ForensicPost
Breaches/Method/File 25-0625

The Authentication That Was Left in Place

Reporting on the aviation incidents describes legacy multi-factor authentication as the weak point. The corpus has filed enrolment, recovery and consent — this is the fourth failure mode of the same control.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetEnterprise authentication estates
ActorScattered Spider
S. Rosler11 min readConfidence: medium2 sources reviewed

Reporting on the 2025 airline incidents identifies legacy multi-factor authentication as a contributing weakness, with older factor mechanisms remaining in service alongside newer ones.

Four Ways This Corpus Has Watched MFA Fail

Enrolment: an attacker registers their own device and holds standing access a password reset does not remove, at 25-0813.

Recovery: the help desk that can reset a factor is persuaded to do so, at 25-0512.

Consent: the factor works correctly and the authenticated user authorises the attacker’s application anyway, at 25-0806.

And legacy: the strong mechanism is deployed, the weak one is left enabled, and the attacker chooses which to face.

Migration Is Why The Weak One Stays

Turning off an older factor strands whoever has not migrated. In an airline that means crew at outstations, contracted ground staff, and agents on equipment the carrier does not control.

So the old mechanism remains enabled for a tail of users, and an authentication estate is only as strong as its weakest enabled option. It is the revocation asymmetry at 25-1207 in a different guise: enabling costs nothing, disabling produces an outage with a name attached to it.

What The Pattern Means For The Advice

"Enable MFA" is the single most repeated recommendation in this field, and the corpus has now recorded four distinct ways an organisation that did enable it was compromised anyway.

The control is still worth having — nothing here argues otherwise. What the corpus can say is that deployment is not the finish line, and that enrolment, recovery, consent and legacy paths are where the attacks land. Graded medium: the legacy characterisation is from research reporting and this desk has not established the mechanism at any named carrier.

This is an analysis file

Built on published research reporting, listed below, read against the identity files in this database. The specific mechanism at any named carrier is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Legacy MFA from major airlines hacked, exposing reams of dataBiometric Update
  2. Key takeaways from the Scattered Spider attacks on insurance firmsPush Security
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary