Cybersecurity COO Disables MFA, Exposing Firm to Attacks

Cybersecurity COO Disables MFA, Exposing Firm to Attacks

First seen 26 Jun 2026, 16:54 UTC TheregisterStreamlinefeed.Co.Ke 83% similarity 66.5
Share:

Article Content

Browse articles
ThreatCluster

A COO at a cybersecurity firm ordered the disabling of multi-factor authentication (MFA) after a minor software glitch affected a few mobile devices. This decision, made without waiting for a technical workaround, left the company vulnerable to credential stuffing and phishing attacks. The IT team had previously implemented MFA to improve the firm's Microsoft Secure Score, but the COO's actions undermined this effort. The issue was traced to a third-party invoicing application that falsely claimed MFA compatibility. Despite identifying the root cause, the COO insisted on an immediate rollback of security protocols. This incident reflects a broader trend of executives bypassing security measures when faced with operational challenges. In Kenya, similar resistance to security protocols is prevalent, with over 1.2 billion cyber threats reported in early 2026. The Central Bank of Kenya has mandated robust MFA in response to rising ransomware attacks.

Key Points: • A COO disabled MFA, exposing the firm to significant security risks. • The issue originated from a faulty third-party invoicing application. • Over 1.2 billion cyber threats were reported in Kenya in early 2026.

ThreatCluster AI

Timeline

2026-06-25
MFA rollout completed
The IT team successfully implemented MFA across the company to enhance security and improve Microsoft Secure Score.
Streamlinefeed.Co.Ke
2026-06-26
COO orders MFA rollback
The COO demanded the immediate disabling of MFA after claiming it crippled financial operations, despite the issue being with a third-party app.
Streamlinefeed.Co.Ke
2026-06-26
Incident reported by IT team
The IT team confirmed that the MFA issue affected only a few devices due to a bug in the invoicing software, not the MFA system itself.
Theregister

Community

Browse all →