Attackers have learned that stealing a password is noisy — but stealing a session token lets them walk straight past multi-factor authentication. Infostealer malware and malicious browser extensions harvest these tokens silently, and the victim's cloud apps simply see a "legitimate" returning session.

Warning signs worth alerting on

Token replay rarely looks perfectly normal. Impossible-travel logins, sessions from data-centre IP ranges, sudden privilege escalations and password-reset emails nobody requested are the classic tells. The key is correlating them: one oddity is noise, three together is an incident.

  • Enforce phishing-resistant MFA and short session lifetimes.
  • Alert on logins from unusual geographies, devices and networks.
  • Require re-authentication for privilege changes and exports.
  • Keep browsers managed — extensions are a favourite token target.
When tokens are stolen, speed beats perfection: revoke first, investigate second.

The first-hour response playbook

Revoke all sessions for the affected accounts, force re-authentication, and rotate credentials that shared the compromised device. Then hunt: review audit logs for data access, forwarding rules and newly registered devices. Only after containment should the longer forensics begin.

Most companies we onboard have none of these detections configured. A one-week security review usually closes the gap — and it is far cheaper than explaining a breach to customers.