Avatier

Attack vector

Session or token theft

Session or token theft is stealing proof that a user already signed in, such as a browser cookie or an access token, and replaying it from another machine. Because the session was created after the password and MFA checks passed, the attacker inherits an authenticated session without needing either factor.

Cookie replay and stolen session tokens.

How attackers use it

Infostealer malware copies browser cookies and saved tokens from an infected device, and proxy phishing kits capture the session cookie the moment a user finishes signing in. The attacker loads that cookie into their own browser and is already inside. Long-lived sessions and refresh tokens can keep that access working for days or weeks.

What breach letters say

None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.

See the Identity Attack Ledger

How to stop it

Shorten session lifetimes for sensitive apps, bind tokens to the device that created them where the platform supports it, and re-check identity on risky actions. Revoke all sessions whenever a password or device is reset.

Terms under this vector

  • Pass-the-cookie

    Pass-the-cookie is an attack in which a stolen browser session cookie is loaded into the attacker's own browser to enter the victim's account.

  • Session hijacking

    Session hijacking is taking over a user's authenticated session, usually by stealing the session token or cookie a site issues after login.

  • Token theft

    Token theft is stealing or forging the digital tokens that prove a user or app is already authenticated, such as session, access, refresh or OAuth tokens.

Threat actors tied to it

Last reviewed Oct 2, 2026