Attackers have learned that stealing a password is noisy — but stealing a session token lets them walk straight past multi-factor authentication. Infostealer malware and malicious browser extensions harvest these tokens silently, and the victim's cloud apps simply see a "legitimate" returning session.
Warning signs worth alerting on
Token replay rarely looks perfectly normal. Impossible-travel logins, sessions from data-centre IP ranges, sudden privilege escalations and password-reset emails nobody requested are the classic tells. The key is correlating them: one oddity is noise, three together is an incident.
- Enforce phishing-resistant MFA and short session lifetimes.
- Alert on logins from unusual geographies, devices and networks.
- Require re-authentication for privilege changes and exports.
- Keep browsers managed — extensions are a favourite token target.
When tokens are stolen, speed beats perfection: revoke first, investigate second.
The first-hour response playbook
Revoke all sessions for the affected accounts, force re-authentication, and rotate credentials that shared the compromised device. Then hunt: review audit logs for data access, forwarding rules and newly registered devices. Only after containment should the longer forensics begin.
Most companies we onboard have none of these detections configured. A one-week security review usually closes the gap — and it is far cheaper than explaining a breach to customers.