Skip to content
Cyber Defense Technologies

Threat Intelligence

Identity Is the New Perimeter: Token Theft, MFA Fatigue and Session Hijacking

As organizations move to cloud services and remote work, attackers increasingly target identities rather than networks. The techniques used to defeat passwords and multifactor authentication, and how to build identity defenses that hold.

By Cyber Defense Technologies June 2, 2026 4 min read

When an organization's email, files, collaboration tools and business applications live in the cloud, the network perimeter matters much less. What matters is who can sign in. Attackers have noticed: many serious intrusions now begin not with an exploit, but with an attacker signing in as someone else.

Multifactor authentication (MFA) was a major step forward, and it still stops a large share of attacks. But attackers have adapted, and some common forms of MFA can be bypassed.

Common identity attack techniques

  1. Password spraying and credential stuffing

    Trying common or leaked passwords across many accounts.

  2. MFA fatigue

    Flooding a user with push prompts until one is approved.

  3. Adversary-in-the-middle phishing

    Proxying a real sign-in to capture passwords and session cookies.

  4. Help desk social engineering

    Convincing support staff to reset passwords or MFA.

  5. Token and session theft

    Stealing session cookies or tokens from devices to bypass MFA entirely.

  6. Abuse of trusted apps and keys

    Consenting malicious applications or using stolen signing keys.

Techniques attackers use

Password spraying and credential stuffing

Attackers try a few common passwords across many accounts (spraying), or reuse credentials leaked from other breaches (stuffing). Accounts without MFA, including forgotten service and test accounts, are prime targets.

MFA fatigue

Attackers who have a password trigger repeated push notifications until a tired or confused user approves one. This technique was reported in several high-profile intrusions in 2022.

Adversary-in-the-middle phishing

Phishing kits proxy a real sign-in page. The victim enters their password and MFA code on what looks like the real site; the kit passes them through and captures the resulting session cookie, which the attacker then uses directly.

Help desk social engineering

Attackers call the help desk impersonating employees and persuade staff to reset passwords or register a new MFA device. CISA and FBI described this tactic in advisories on the group known as Scattered Spider.

Token and session theft

Malware on a device, often an information stealer, extracts browser session cookies and tokens, which allow attackers to use a session without ever needing the password or MFA.

Abuse of applications and keys

Attackers trick users into granting permissions to malicious applications, or abuse existing application permissions. In more sophisticated cases, stolen signing keys have been used to forge authentication tokens; the U.S. Cyber Safety Review Board examined one such case affecting cloud email accounts in a 2024 report.

Building identity defenses

Phishing-resistant MFA

FIDO2 security keys and passkeys are bound to the legitimate site, so they cannot be relayed through a phishing proxy. Prioritize them for administrators, executives and high-risk users, then expand. Where push notifications are used, enable number matching and additional context.

Conditional access and device trust

Require sign-ins to come from managed, compliant devices for sensitive applications, and evaluate risk signals such as unusual locations or impossible travel.

Protect sessions

Shorten session lifetimes for sensitive applications, bind tokens to devices where supported, and revoke sessions quickly when an account is suspected of compromise, not only reset the password.

Harden the help desk

Verify identity before resets using methods an attacker cannot easily fake: callbacks to known numbers, manager approval, or in-person verification for privileged accounts.

Control application consent

Restrict which applications users can authorize, and review existing application permissions regularly.

Monitor identity activity

Alert on impossible travel, unusual MFA registrations, mass MFA prompts, new application consents, privilege changes and sign-ins from anonymizing infrastructure.

Protect the identity system itself

Identity providers, directory services and signing keys are the keys to the kingdom. Restrict and monitor administrative access to them, protect keys in hardware where possible, and plan how you would respond to their compromise.

Frequently asked questions

Is MFA still worth it if it can be bypassed? Absolutely. MFA stops the large majority of credential attacks. The point is to move toward forms that resist the bypass techniques now in use.

Does resetting a password end an attacker's access? Not always. Stolen session tokens can remain valid after a password change. Revoke sessions and review registered MFA methods and application permissions too.

Where should we start? Enforce MFA everywhere, then move administrators and high-risk users to phishing-resistant methods, and harden help desk procedures.

What to do this week

  • Find accounts without MFA, including service, test and break-glass accounts, and decide how each will be protected.
  • Enable number matching for push-based MFA.
  • Review which third-party applications users have authorized, and remove unneeded ones.
  • Test your help desk's reset process: could a caller impersonating an executive get a password or MFA reset?
  • Confirm you can revoke all sessions for a user quickly, not only reset their password.

How CDT can help

CDT's penetration testing and red team exercises test identity controls against the techniques attackers use today, and our secure systems engineering team designs identity architectures that hold up. Social engineering assessments test your help desk.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.