Token Theft and Session Hijacking: What MFA Does Not Cover

Many organizations have turned on multifactor authentication and breathed a sigh of relief. That was the right move, and it blocks a large share of password-based attacks. But attackers have adapted. One technique, called adversary-in-the-middle phishing, can get around common forms of MFA without ever guessing a password or code.

Understanding how it works helps you decide which additional protections are worth the effort.

How adversary-in-the-middle phishing works

In an ordinary phishing attack, a fake page collects your password and the attacker uses it later. MFA defeats that, because the attacker lacks the code.

In an adversary-in-the-middle attack, the fake page acts as a relay. The victim clicks a link in an email or text and lands on a page that looks exactly like the real Microsoft 365 sign-in. Behind the scenes, the attacker's server passes everything the victim types to the real service and passes the real responses back. The victim enters a password and approves the MFA prompt or types a code, and the real service accepts it.

Here is the problem. After a successful sign-in, the service gives the browser a session token, a small credential that says this user is already verified. The attacker's relay captures that token. With it, the attacker can open the mailbox or files as that user, with no password or MFA prompt required, until the session expires or is revoked.

What MFA does and does not cover

MFA protects the moment of sign-in against stolen passwords. It does not protect:

A session token that has already been issued and then copied.

Users who approve a prompt on a convincing fake page.

Sign-ins that rely on codes or push approvals that can be relayed.

This is why you may hear about an account being taken over even though MFA was on. It does not mean MFA is worthless. It means MFA is one layer.

What attackers do with a stolen session

Once inside a mailbox, attackers commonly look for invoices and payment conversations, create hidden inbox rules to conceal their activity, send further phishing from the trusted account, or register their own MFA method to keep access. In healthcare, a hijacked mailbox may expose protected health information, which can trigger breach analysis obligations under HIPAA.

Controls that reduce the risk

Phishing-resistant sign-in

Methods based on FIDO2 security keys or passkeys tie authentication to the real website's address. A fake page on a different domain cannot complete the sign-in, which defeats the relay trick. Consider these first for administrators, finance staff and anyone with broad access, then expand as practical.

Conditional access and device checks

Where your licensing allows, set rules about when sign-ins are accepted. Requiring a managed, compliant device, or limiting sign-ins from unexpected countries, makes a stolen token much harder to use from the attacker's computer.

Shorter sessions and quick revocation

Limit how long sessions last for sensitive roles, and know how to revoke all sessions for a user quickly if compromise is suspected. Resetting a password alone may not end an existing session.

Better monitoring

Watch for signs of token theft: sign-ins from unusual locations right after a normal one, new inbox forwarding rules, newly registered MFA methods and impossible travel. Alerts on these events shorten the time an attacker has.

User awareness

Teach staff to look at the address bar, to be suspicious of unexpected sign-in requests, and to report anything odd quickly. Make it easy to say, "I think I clicked something."

A practical order of work

Confirm MFA is on for every account, with no exceptions.

Move administrators and high-risk roles to phishing-resistant methods.

Add device and location conditions to sign-in policies.

Review session lifetime settings and practice session revocation.

Turn on alerting for risky sign-ins and mailbox rule changes.

Working with UnityCare IT

If you have MFA in place and wonder what comes next, this is the next step. UnityCare IT can review your sign-in policies, help roll out phishing-resistant methods where they matter most, and set up monitoring for the warning signs. We can also walk through an incident plan so your team knows what to do if a session is hijacked.

Related service

An outsourced IT department with proactive maintenance and one number to call.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172