top of page

Adversary-in-the-Middle Phishing Is Stealing Live Sessions and Walking Straight Past Multi-Factor Authentication in 2026

  • Writer: TrustSphere Network
    TrustSphere Network
  • 4 days ago
  • 4 min read

For years the industry's answer to phishing was to add a second factor. If a stolen password alone could no longer open an account, the reasoning went, then the whole economics of credential theft would collapse. Multi-factor authentication did raise the bar meaningfully, and it retired a generation of simple password-reuse attacks. But it protected one specific moment — the act of logging in — and attackers, as they always do, moved to the moment just after it.


In 2026 the dominant technique is adversary-in-the-middle phishing, in which the victim is lured to a proxy page that sits invisibly between them and the real service. The page relays the genuine login screen, captures the username, password and one-time code as they are entered, and — crucially — steals the authenticated session cookie the service issues once the second factor is satisfied. With that cookie replayed into their own browser, the attacker inherits a fully authenticated session without ever needing to pass an MFA challenge themselves, because the victim already did.


For financial institutions the intrusion surfaces not as a failed login but as a successful, correctly authenticated session that happens to originate from the wrong place. The phishing proxy is invisible to the bank; what remains observable is a session resumed from a new device or network, sometimes near-simultaneously with the customer's own, followed by the reconnaissance and payment activity of an account takeover that walked in through the front door the customer opened.


Regulatory and Market Context


Regulators and standards bodies have been clear that authentication strength alone is no longer sufficient assurance. The FCA's operational-resilience and fraud expectations, alongside the strong-customer-authentication regime under PSD2, established MFA as a baseline, but supervisors increasingly expect firms to detect compromise that occurs after a successful authentication rather than treating a passed challenge as the end of the risk.


Guidance from national cyber authorities has specifically highlighted session-token theft and phishing-as-a-service kits as a maturing threat.


The market reading is that the industry over-invested in the login event and under-invested in everything that follows it. As phishing-as-a-service platforms package adversary-in-the-middle capability into point-and-click kits, stealing a session has become as accessible as stealing a password once was. The defensive centre of gravity is shifting from proving who logged in toward continuously assessing whether the session still belongs to that person.


What the Data Is Showing


TrustSphere's engagement data shows session-hijack takeovers clustering around a recognisable post-authentication signature even though the phishing proxy is invisible to the bank. A session that resumes from a new device, network or geography inconsistent with the customer's established pattern, changes to contact details or payees early in the session, and rapid movement toward high-value actions recur across cases regardless of how the cookie was captured.


The behavioural markers are those of a stranger operating a valid session rather than a customer continuing their own. An impossible-travel jump between the legitimate login and the resumed session, a device or browser fingerprint never seen on the account, immediate navigation to beneficiary or credential-change screens, and payment activity that breaks the customer's normal rhythm together separate a hijacked session from a genuine one — even though the authentication that opened it was entirely valid.


Implications for Financial Institutions


The practical implication is that authentication cannot be treated as a one-time gate. Institutions need continuous, session-long risk assessment that watches device, network and behavioural signals after login and can challenge or terminate a session when they diverge from the authenticated customer's baseline, rather than trusting a session indefinitely because it began with a passed MFA check. Binding sessions more tightly to a device and shortening the useful life of a stolen token materially reduce the value of adversary-in-the-middle theft.


There is a defence-in-depth dimension aimed at the login itself. Phishing-resistant, origin-bound authentication such as passkeys removes the relayable one-time code that adversary-in-the-middle kits depend on, while customer education about proxy phishing helps at the margin. Firms that combine phishing-resistant authentication with continuous session monitoring and step-up on sensitive actions will disrupt an attack designed specifically to make a valid login the last checkpoint it ever has to pass.


Conclusion


Adversary-in-the-middle phishing has turned the session, not the password, into the prize, letting attackers inherit an authenticated session without ever facing the second factor. The bank cannot see the proxy that stole the cookie, but it can see the session that resumes from the wrong device and immediately reaches for payees and credentials. Institutions that respond well will treat authentication as continuous rather than a single gate, adopt phishing-resistant methods that break the relay, and monitor sessions after login so a stolen token cannot quietly become a drained account.


Suggested Next Steps


  • Move from one-time login checks to continuous, session-long risk assessment of device, network and behavioural signals, with the ability to challenge or terminate mid-session.

  • Adopt phishing-resistant, origin-bound authentication such as passkeys to remove the relayable one-time codes that adversary-in-the-middle kits capture.

  • Detect impossible-travel and unfamiliar-device session resumption, and step up on early changes to contact details, payees or credentials.

  • Bind sessions to devices and shorten token lifetimes so a stolen session cookie loses value quickly.


Sources: FCA expectations on operational resilience and fraud controls; strong-customer-authentication requirements under PSD2/SCA; NCSC and CISA guidance on phishing-resistant authentication and session-token theft; FIDO Alliance material on passkeys and phishing-resistant authentication; TrustSphere Risk Index — April 2026.


TrustSphere Risk Index — Vendor Spotlight: Push Security


In TrustSphere's April 2026 Risk Index, Push Security scored 61% in the Identity Threat Detection & Session Protection category, reflecting a focused approach to browser-side session and identity risk weighed against the breadth of controls a full account-takeover defence requires.


Push Security's core strength is visibility into the browser and identity layer where adversary-in-the-middle attacks actually operate — observing logins, detecting phishing-proxy patterns and surfacing stolen or replayed session activity close to where the theft happens. In a threat model where the login is valid and the danger lies in a hijacked session, instrumentation at the identity and browser layer is directly relevant to catching compromise the authentication event will never reveal.


The watch-item is that stopping account takeover end to end still depends on how identity-layer signals feed the bank's own session monitoring and payment controls, since the fraudulent value movement happens inside the banking session. Buyers should weigh how Push Security's identity-threat signals integrate with device intelligence, behavioural monitoring and step-up controls, treating browser-side detection and transaction-side defence as complementary layers rather than expecting either to stop a session-hijack takeover alone.


TrustSphere helps financial institutions design and deploy intelligent fraud and financial crime detection solutions. Visit www.trustsphere.ai

 
 
 

Comments


Recommended by TrustSphere

© 2026 TrustSphere.ai. All Rights Reserved.

  • LinkedIn

Disclaimer for TRUSTSPHERE.AI

The content provided on the TRUSTSPHEREAI website is intended for informational purposes only. While we strive to provide accurate and up-to-date information, the data and insights presented are generated from a contributory network and consolidated largely through artificial intelligence. As such, the information may not be comprehensive, and we do not guarantee the accuracy, reliability, or completeness of any content.  Users are advised that important decisions should not be made based solely on the information provided on this website. We encourage users to seek professional advice and conduct their own research prior to making any significant decisions.  TruststSphere Partners is a consulting business. For a comprehensive review, analysis, or support on Technology Assessment, Strategy, or go-to-market strategies, please contact us to discuss a customized engagement project.   TRUSTSPHERE.AI, its affiliates, and contributors shall not be liable for any loss or damage arising from the use of or reliance on the information provided on this website. By using this site, you acknowledge and accept these terms.   If you have further questions,  require clarifications, or requests for removal or content or changes please feel free to reach out to us directly.  we can be reached at hello@trustsphere.ai

bottom of page