From Credential Theft to Token Theft: The Evolution of Phishing
As organizations have strengthened account protection through widespread adoption of multi-factor authentication (MFA), phishing attacks have evolved accordingly. Modern attackers increasingly bypass MFA by performing token theft rather than just stealing the usernames and passwords.
This presentation examines the evolution of phishing from traditional credential-harvesting campaigns to adversary-in-the-middle (AiTM) frameworks capable of stealing session tokens and compromising MFA-protected accounts. Attendees will gain insight into how these attacks are executed, the infrastructure that supports them, and the implications for identity security. The session also covers practical detection and mitigation strategies to reduce the risk of account takeover in modern identity environments.
