Attack vector
Session or token theft
Session or token theft is stealing proof that a user already signed in, such as a browser cookie or an access token, and replaying it from another machine. Because the session was created after the password and MFA checks passed, the attacker inherits an authenticated session without needing either factor.
Cookie replay and stolen session tokens.
How attackers use it
Infostealer malware copies browser cookies and saved tokens from an infected device, and proxy phishing kits capture the session cookie the moment a user finishes signing in. The attacker loads that cookie into their own browser and is already inside. Long-lived sessions and refresh tokens can keep that access working for days or weeks.
What breach letters say
None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.
How to stop it
Shorten session lifetimes for sensitive apps, bind tokens to the device that created them where the platform supports it, and re-check identity on risky actions. Revoke all sessions whenever a password or device is reset.
Terms under this vector
- Pass-the-cookie
Pass-the-cookie is an attack in which a stolen browser session cookie is loaded into the attacker's own browser to enter the victim's account.
- Session hijacking
Session hijacking is taking over a user's authenticated session, usually by stealing the session token or cookie a site issues after login.
- Token theft
Token theft is stealing or forging the digital tokens that prove a user or app is already authenticated, such as session, access, refresh or OAuth tokens.
Threat actors tied to it
- ALPHV Blackcat
Profile with government sources
- APT29
Profile with government sources
Last reviewed Oct 2, 2026