The team at Stingrai recently published one of the better explanations I’ve seen of Adversary in the Middle (AiTM) phishing attacks and why they’ve become one of the fastest-growing threats facing enterprises today. Their article explains not only how these attacks work, but why organizations that have already deployed multi factor authentication are still finding themselves compromised. It’s well worth reading because it highlights a difficult truth many security teams are just beginning to accept: successful authentication no longer means the right person logged in.
AiTM attacks don’t defeat authentication in the traditional sense. Instead, they insert themselves between the employee and the legitimate login page. The victim signs into what appears to be Microsoft 365, Google Workspace, or another trusted service, enters their password, completes their MFA challenge, and believes everything worked exactly as expected. In reality, the attacker has been transparently relaying the entire session to the legitimate service, capturing the authenticated session token that is issued after login. At that point, the attacker doesn’t need your password anymore. They simply inherit your authenticated session and become you.
That distinction is incredibly important because it explains why so many organizations continue to suffer breaches despite rolling out authenticator apps, SMS codes, or push notifications. These technologies verify that someone completed an authentication challenge. They do not always verify that the authentication originated from the legitimate site, that the correct hardware is present, or that the authenticated session cannot later be abused. As the Stingrai article notes, attackers have increasingly shifted their attention to the session and authorization layers because that’s where many existing defenses end.
The cybersecurity industry has responded largely by trying to detect these attacks after they occur. We analyze impossible travel events. We inspect session anomalies. We revoke stolen tokens. We hunt for suspicious OAuth applications. These are valuable capabilities, but they are all reactive. They assume the attacker has already crossed the front door and the race becomes one of discovering them before they accomplish their objective.
A better approach is to prevent the authentication from succeeding in the first place.
This is where Token takes a fundamentally different approach than legacy MFA. Instead of asking a user to approve a notification or type a one time code, Token requires four conditions before authentication is ever completed. The request must originate from the legitimate registered domain. The registered Token device must be physically present near the system requesting authentication. The authorized user must provide a live fingerprint on the device. Finally, the cryptographic challenge must be signed using the private key securely stored inside the Token hardware. If any one of those conditions is missing, authentication simply does not occur. There is no code to steal, no push notification to approve, and no reusable credential for an attacker to relay. This architecture is consistent with the phishing resistant principles discussed in the Stingrai article while extending them with dedicated biometric hardware and physical proximity requirements.
The most significant shift occurring in cybersecurity today is that attackers are no longer trying to break through your firewall. They are logging in with valid identities. That means identity has become the new security perimeter. Every major breach over the past year reinforces that lesson. Organizations continue investing heavily in detecting attackers after they enter the network, yet comparatively little attention is paid to making those initial logins impossible to abuse.
The Stingrai article ends with practical recommendations for detecting AiTM attacks. Those recommendations are sound and organizations should implement them. But the larger question every CISO should ask is this: why rely solely on detecting a stolen session after authentication, when modern authentication technologies can prevent that session from ever being created for an attacker?
That’s the difference between chasing intruders through your network and locking the front door before they ever get inside.