<?xml version="1.0" encoding="UTF-8"?>
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:ali="http://www.niso.org/schemas/ali/1.0/" article-type="research-article" xml:lang="en" dtd-version="1.3">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">FOREK</journal-id>
      <journal-title-group>
        <journal-title>Informatic and Elektronic Technology Journal</journal-title>
        <abbrev-journal-title>FOREK</abbrev-journal-title>
      </journal-title-group>
      <publisher>
        <publisher-name>Informatic and Elektronic Technology Journal</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <title-group>
        <article-title>Beyond Phishing: Detecting MFA Fatigue and Adversary-in-the-Middle at Scale</article-title>
      </title-group>
      <contrib-group/>
      <pub-date publication-format="electronic">
        <year>2025</year>
        <month>10</month>
        <day>29</day>
      </pub-date>
      <permissions>
        <copyright-statement>Copyright (c) 2026 Informatic and Elektronic Technology Journal</copyright-statement>
        <copyright-year>2026</copyright-year>
        <copyright-holder>Informatic and Elektronic Technology Journal</copyright-holder>
      </permissions>
      <abstract>
        <p>This study proposes a defender-centric strategy to detect and contain two fast-rising attack patterns—MFA fatigue and Adversary-in-the-Middle (AiTM)—without relying on expensive tooling. We introduce a lightweight pipeline that fuses identity telemetry (push frequency anomalies, impossible travel), web gateway indicators (suspicious reverse-proxy domains), and endpoint signals (token theft heuristics) into actionable detections. Evaluated across 15 small-to-medium organizations, the approach reduced median time-to-detect by 63% and cut successful account takeovers by 41% over eight weeks. We document failure modes (e.g., noisy travel baselines), provide hardening tips (phishing-resistant MFA, conditional access, token binding), and publish query patterns that can be adapted to common SIEM/XDR platforms. The results indicate that defenders can meaningfully blunt modern phishing and session-hijacking campaigns with modest engineering effort and targeted telemetry enrichment.</p>
      </abstract>
    </article-meta>
  </front>
  <body/>
</article>
