You’ve done the sensible things. Long passwords. Multi-factor authentication switched on. Staff trained not to click dodgy links. So you’d be forgiven for thinking your accounts are locked up tight.
Here’s the uncomfortable bit: there’s a type of attack that doesn’t need your password at all. It doesn’t need your MFA code either. It quietly steps around both, and for a lot of businesses it’s completely off the radar.
It’s called session hijacking, and it’s worth understanding – not because you need to become a security expert, but because knowing it exists changes how seriously you take a few everyday habits.
First, what’s a “session”?
When you log into something – your email, your accounting software, your Microsoft 365 – you don’t type your password again every time you click a new page. You log in once, and the system remembers you for a while. That “being remembered” is your session.
Behind the scenes, the website gives your browser a little file called a session token, or cookie. Think of it like a wristband at a festival. You show your ticket once at the gate, they check it, and you get a wristband. After that, nobody asks for your ticket again – the wristband is enough to get you in and out all day. It proves you already passed the check.
That system is convenient, and it’s how the whole web works. The problem is what happens if someone manages to copy your wristband.
How attackers get hold of your session
If a criminal can steal that session token, they don’t need your password or your MFA code. They just present the stolen token, and the system waves them through as if they were you. You’ve already done the hard part of logging in – they’re simply borrowing the result.
So how do they get it? A few common ways.
Malware on a device is a big one. If a member of staff picks up an information-stealing infection – often from a dodgy download or attachment – it can quietly scoop up session tokens stored in the browser and send them off to the attacker.
Dodgy public Wi-Fi is another. On an unsecured network, a nearby attacker can sometimes intercept the traffic between someone’s laptop and the websites they’re using, plucking out tokens as they go.
Then there’s phishing that’s specifically designed to grab tokens. Some of the more sophisticated fake login pages don’t just steal your password – they sit in the middle, pass your details through to the real site, and capture the session that comes back. You think you’ve logged in normally. You have. It’s just that someone else now holds a copy of the session too.
Why this one slips past your usual defences
This is what makes session hijacking so sneaky: it turns your own successful login against you.
Multi-factor authentication is brilliant, and everyone should use it. But MFA does its job at the front door – it checks who you are when you log in. Once you’re in and holding a valid session, MFA has already done its bit. A stolen token represents an account that’s already past that checkpoint, which is exactly why this attack sidesteps it.
The same goes for a strong password. It doesn’t matter how long or clever your password is if the attacker never needs to type it.
That’s not a reason to drop MFA or slacken off on passwords – far from it, they stop a huge range of other attacks. It’s a reason to understand that they aren’t the whole story.
What actually helps
The good news is that defending against this doesn’t mean undoing everything you’ve built. It means adding a few sensible layers and habits on top.
Keep devices clean and updated. Since a lot of token theft starts with malware, solid, up-to-date security software on every device does a lot of heavy lifting. Browsers and operating systems that are kept patched close off many of the routes attackers use.
Be careful on public Wi-Fi. Encourage staff to avoid logging into sensitive business systems on random open networks – or to use a VPN, which scrambles their traffic so it can’t be plucked out of the air.
Log out of things properly. A session that’s been ended can’t be hijacked. Signing out of sensitive systems when you’re finished, rather than leaving them open indefinitely, genuinely reduces the window of risk.
Watch for the odd behaviour. Many business systems can flag when an account suddenly logs in from a strange location or an unfamiliar device. Having someone keeping an eye on that – and acting quickly when something looks off – is often what catches a hijacked session before it does damage.
Keep training current. Staff who understand that a convincing login page can still be a trap, and that “but I had MFA on” isn’t a force field, make better decisions in the moment.
Where this leaves you
None of this means your MFA and passwords were a waste of time – they’re doing essential work every day. Session hijacking is a reminder that security isn’t a single lock you fit once and forget. It’s layers, kept in good repair, watched over by someone who’ll notice when something’s not right.
For most SMEs, the tricky part isn’t understanding the risk – it’s having the time and know-how to keep all those layers in place while running a business. That’s exactly the sort of thing worth handing to people who do it all day.
If you’d like to be confident that your business is protected against the threats that slip past the obvious defences, we can help you put the right layers in place and keep a watchful eye on your systems.
Talk to Provident IT about protecting your business from every angle – take a look at our IT Security service here.

