Avatier

Session or token theft

Token theft

Also called: session token replay

Token theft is stealing or forging the digital tokens that prove a user or app is already authenticated, such as session, access, refresh or OAuth tokens. A valid token lets the attacker act as that identity without a password or MFA. Tokens can be copied from devices, intercepted in transit, or forged with a stolen signing key.

How it works

Attackers take tokens from browser storage, log files, misconfigured apps or compromised integrations, then replay them against the service that issued them. With a stolen signing key, they can mint new tokens outright. Refresh tokens are especially valuable because they can be traded for fresh access tokens for days or weeks.

A real example

The Cyber Safety Review Board reported in 2024 that the Storm-0558 actor accessed Exchange Online mailboxes of 22 organizations and over 500 individuals using authentication tokens signed by a key Microsoft had created in 2016.

Source: Review of the Summer 2023 Microsoft Exchange Online Intrusion — Cyber Safety Review Board (published by CISA), 2024-03-20

How to stop it

Keep token lifetimes short, bind tokens to the device or client they were issued to, revoke refresh tokens when risk changes, and protect and rotate signing keys.

Related terms

Threat actors that use it

  • APT29

    Profile with government sources

Sources

  1. Review of the Summer 2023 Microsoft Exchange Online Intrusion — Cyber Safety Review Board (published by CISA), 2024-03-20

Last reviewed Oct 2, 2026