Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is session hijacking?

Session hijacking is unauthorised use of an existing authenticated session.

Instead of defeating the login process again, the attacker uses session material that the service already trusts.

Identify the actual session

Do not start with geography alone.

Look for:

  • session ID;
  • token family;
  • browser/application;
  • device fields;
  • source infrastructure;
  • user agent;
  • activity tied to that session;
  • session creation and revocation.

A useful example might look like:

Example session activity
session=SES-4C18created=08:14 from known laptoplater use=11:02 from unfamiliar browserfresh authentication=none recordedaccount change=forwarding rule added

That gives you a defined session to investigate.

Test legitimate explanations

The same account may appear from different places because of:

  • VPN;
  • mobile networks;
  • corporate proxy;
  • authorised second device;
  • remote desktop;
  • shared access.

So correlate the session with device and account activity rather than calling every location change hijacking.

Look for unauthorised continuation

Useful evidence may include:

  • browser/session theft artefacts;
  • malware;
  • token use without reauthentication;
  • unfamiliar account actions inside the same session;
  • device mismatch;
  • provider security alerts.
Known sessionAuthenticated state existsProvider identifies the session.
Unexpected reuseSession appears from another routeDevice/client/infrastructure changes.
Account activityUnauthorised actions followContext supports misuse of the session.

The practical point is: prove unauthorised use of a defined session through its identifiers and activity. Geography and missing login records are supporting features, not the whole proof.

Reference: CIM-053Cyber Incidents & Offender Methods