Reporting on the 2025 airline incidents identifies legacy multi-factor authentication as a contributing weakness, with older factor mechanisms remaining in service alongside newer ones.
Four Ways This Corpus Has Watched MFA Fail
Enrolment: an attacker registers their own device and holds standing access a password reset does not remove, at 25-0813.
Recovery: the help desk that can reset a factor is persuaded to do so, at 25-0512.
Consent: the factor works correctly and the authenticated user authorises the attacker’s application anyway, at 25-0806.
And legacy: the strong mechanism is deployed, the weak one is left enabled, and the attacker chooses which to face.
Migration Is Why The Weak One Stays
Turning off an older factor strands whoever has not migrated. In an airline that means crew at outstations, contracted ground staff, and agents on equipment the carrier does not control.
So the old mechanism remains enabled for a tail of users, and an authentication estate is only as strong as its weakest enabled option. It is the revocation asymmetry at 25-1207 in a different guise: enabling costs nothing, disabling produces an outage with a name attached to it.
What The Pattern Means For The Advice
"Enable MFA" is the single most repeated recommendation in this field, and the corpus has now recorded four distinct ways an organisation that did enable it was compromised anyway.
The control is still worth having — nothing here argues otherwise. What the corpus can say is that deployment is not the finish line, and that enrolment, recovery, consent and legacy paths are where the attacks land. Graded medium: the legacy characterisation is from research reporting and this desk has not established the mechanism at any named carrier.
Built on published research reporting, listed below, read against the identity files in this database. The specific mechanism at any named carrier is not established. Corrections: corrections@forensicpost.com.