Latest Trending Discover Timelines Categories
←All explainers

Technology explainer

How Can Phishing Steal a Session After Multi-Factor Authentication?

A real-time phishing proxy can relay a genuine sign-in, collect a password and one-time code, then capture the authenticated session token. Phishing-resistant, origin-bound credentials change that trust model.

Multi-factor authentication blocks many attacks because a password alone is not enough. It does not, however, guarantee that the person is signing in through the correct path. An adversary-in-the-middle phishing service exploits that distinction.

The real-time relay

The victim opens a link that resembles a trusted cloud service. Behind the page, the attacker runs a proxy that forwards requests to the genuine provider. The victim enters a password and then a one-time code or approves a prompt. Because those values reach the real service immediately, the authentication can succeed.

The legitimate service then creates an authenticated session and returns a session token, often stored as a browser cookie. The proxy can copy that token before relaying the response to the victim. Reusing it may let the attacker act as the already authenticated user until the session expires or is revoked.

Why the page can look convincing

Browser-in-the-browser overlays can imitate a separate sign-in window, including a familiar address bar. Some kits also relay genuine pages, so branding, error messages and conditional-access checks behave normally. A correct-looking Microsoft or Google page is therefore not sufficient proof that the full navigation path is safe.

What changes the outcome

Passkeys and hardware security keys use origin-bound cryptography. The authenticator signs a challenge only for the registered website, so a lookalike domain or proxy cannot obtain a reusable response for the legitimate origin. Organizations should also shorten sensitive sessions, monitor unusual token use, revoke suspected sessions and require fresh authentication for high-risk actions.

Users can reduce risk by opening important services through saved bookmarks, checking unexpected professional outreach through another channel and reporting suspicious links. Multi-factor authentication remains valuable, but methods that resist phishing are stronger than codes that can be relayed in real time.

First appeared in

AI Policy Invitations Hid a Microsoft 365 Session Trap

A new version of NewTqnia is ready.