We just experienced a successful phishing attack even with MFA enabled.
Do you use Conditional Access and only allow access from hybrid joined or compliant devices?