ARToken: How attackers are bypassing MFA and maintaining access

ARToken: How attackers are bypassing MFA and maintaining access

July 15, 2026 · 18 min

About this episode

This episode discusses how ARToken can bypass MFA and maintain access through sophisticated phishing techniques.

MFA and password resets aren't always enough. That’s terrifying for security teams today. In this episode of Talos Takes, we dive deep into ARToken, a sophisticated phishing/BEC-as-a-service platform that steals credentials, bypasses MFA entirely, and leverages primary refresh tokens (PRTs) to maintain persistence in your environment long after a password reset. This turns a simple phishing click into a long-term breach. It’s time to rethink your defenses. Join us as Cisco Talos Threat Resear...

More episodes of Talos Takes

Explore listener stats, chart rankings, contacts and more on the Talos Takes podcast page.