Session Tokens Are the Real Target
For most of the past decade, security advice on credential attacks reduced to a single instruction. Turn on multi-factor authentication. That instruction was correct and it worked, which is precisely why attackers stopped attacking the thing it protects. The current generation of credential campaigns does not try to defeat MFA. It waits for the victim to complete it, then steals what the authentication produced. The password was never the prize. The session was.