Security Glossary

What is Session Hijacking?

Session hijacking lets an attacker reuse an already-authenticated session — browser cookies, tokens, or SSO artifacts — instead of guessing your password. MFA that only protects login can be bypassed if the session itself is stolen.

How a Session Hijacking Attack Works

1

Deliver malware or a malicious proxy

Infostealers and adversary-in-the-middle kits capture cookies after login.

2

Replay the session

Stolen cookies open webmail or SaaS as the victim without a new MFA prompt.

3

Raise privileges

From the hijacked session, attackers search for admin tools and secrets.

4

Persist

New forwarders, OAuth apps, or local accounts keep access after cookie expiry.

Real-World Example

An employee's browser cookies for Microsoft 365 were stolen by an infostealer. Attackers accessed mail the same afternoon without triggering a new MFA challenge and set inbox rules to hide fraud threads.

How AiVERSARY Detects Session Hijacking Risk

AiVersary does not replace endpoint security, but it shows which public cues make employees attractive phishing targets for the malware that enables session theft.

Is your organization exposed to session hijacking?

AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.

Get Your Threat Report

Related Terms

Credential Stuffing

Credential stuffing is when attackers take usernames and passwords leaked from one breach and automatically try them on other services. Because most people reuse passwords, a breach at a shopping site or social network can give attackers working credentials for your corporate email, VPN, or cloud platforms. It is automated, fast, and alarmingly effective.

OAuth Phishing

OAuth phishing does not always steal your password. It tricks you into clicking "Allow" on a third-party app consent screen, granting mailbox or files access to an attacker-controlled application — access that can survive a password change.

MFA Fatigue

MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.

Tenant Compromise

Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.