Token theft
Also called: session token replay
Token theft is stealing or forging the digital tokens that prove a user or app is already authenticated, such as session, access, refresh or OAuth tokens. A valid token lets the attacker act as that identity without a password or MFA. Tokens can be copied from devices, intercepted in transit, or forged with a stolen signing key.
How it works
Attackers take tokens from browser storage, log files, misconfigured apps or compromised integrations, then replay them against the service that issued them. With a stolen signing key, they can mint new tokens outright. Refresh tokens are especially valuable because they can be traded for fresh access tokens for days or weeks.
A real example
The Cyber Safety Review Board reported in 2024 that the Storm-0558 actor accessed Exchange Online mailboxes of 22 organizations and over 500 individuals using authentication tokens signed by a key Microsoft had created in 2016.
Source: Review of the Summer 2023 Microsoft Exchange Online Intrusion — Cyber Safety Review Board (published by CISA), 2024-03-20
How to stop it
Keep token lifetimes short, bind tokens to the device or client they were issued to, revoke refresh tokens when risk changes, and protect and rotate signing keys.
Related terms
Threat actors that use it
- APT29
Profile with government sources
Sources
- Review of the Summer 2023 Microsoft Exchange Online Intrusion — Cyber Safety Review Board (published by CISA), 2024-03-20
Last reviewed Oct 2, 2026