Skip to content
CIM-055 Cyber Incidents & Offender Methods

What is adversary-in-the-middle authentication theft?

Adversary-in-the-middle authentication theft occurs when an offender places infrastructure between the user and the genuine service to capture or relay authentication material.

Avoid the dangerous assumption

The dangerous assumption is that multi-factor authentication makes every successful login trustworthy.

It does not.

The victim may be directed to a convincing phishing page that relays their credentials and authentication challenge to the genuine service in real time.

The offender may then capture the resulting session material and use the authenticated session.

The user may see the genuine service content and believe the login succeeded normally.

Evidence may include:

  • a phishing link
  • a fake or relay website
  • authentication events close in time
  • session or token use from different infrastructure
  • browser and network records
  • provider risk alerts
  • subsequent account activity
  • hosting and domain records.

Investigators should separate the stages:

  • the victim visited the phishing infrastructure
  • credentials were entered
  • authentication was relayed
  • multi-factor approval occurred
  • session material was issued
  • the session was later used.

One stage does not automatically prove the next.

Do not assume that an approved multi-factor prompt proves the user intended to authorise the offender. The user may have believed they were signing into the genuine service.

Current provider terminology and protections vary, so product-specific claims require verification.

The technique may explain how an offender gained access without defeating the cryptography behind multi-factor authentication.

It does not automatically identify who operated the relay infrastructure or used the resulting session.

Operational takeaway

Consider real-time relay where phishing, multi-factor approval and rapid session use occur together, and preserve the website, authentication, session and device records.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.