Session Theft & MFA Limits

    MFA Helps. It Is Not Magic.

    Some phishing kits steal your signed-in session after MFA. Phishing-resistant sign-in closes that gap.

    Everyday Cyber SafetyEveryday usersIT & help deskLeadership

    Illustrative scenario

    How It Looks in Real Life

    You sign in through a link, complete MFA normally, and land in your mailbox. Later, IT sees your account accessed from another country, without any MFA prompt.

    Understand it

    How the Attack Works

    Adversary-in-the-middle pages sit between you and the real site. You complete MFA, but the page captures the session token issued afterwards, letting the attacker reuse your signed-in session. Passkeys and security keys resist this because they check the real site address.

    Red flags

    Warning Signs

    • Signing in through a link instead of a bookmark or app.
    • Address bar showing a domain that is close to, but not, the real one.
    • Sign-in alerts from unfamiliar locations shortly after you signed in.

    Safer habits

    What to Do Instead

    • 1Open important services from bookmarks or official apps.
    • 2Use passkeys or security keys where your organisation supports them.
    • 3Report unexpected sign-in alerts promptly.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.
    If you: approved app permissions or a sign-in request
    1. 1Report it straight away so IT can revoke the session or app consent.
    2. 2Remove the unfamiliar app from your account’s connected apps or permissions page.
    3. 3Changing your password does not remove app permissions or tokens already issued.

    Knowledge Check

    What Would You Do?

    Which statement is accurate?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us