The attack that laughs at your password

You did everything right. Strong password, multi-factor authentication turned on, the works. And an attacker still logged into your account without triggering a single prompt. No password needed, no code, no approval on your phone. They just walked in.

Sounds impossible. It isn’t, and it’s one of the fastest-growing attacks hitting small businesses right now. It’s called session hijacking, and it works by stealing something you’ve probably never thought about: your login cookies.

What a cookie really is

When you log into a website and check the ‘keep me signed in’ box, the site doesn’t make you type your password every time you come back. Instead it hands your browser a little file called a session cookie. Think of it as a wristband at a concert. You showed your ID once at the door, they gave you the wristband, and now you flash the wristband to get back in. Nobody checks your ID again.

That wristband is the whole point of the attack. If a hacker can grab your session cookie, they can flash it at the website and get waved right in as you. And here’s the brutal part: because you already proved who you were when the cookie was created, the site doesn’t ask for your password or your MFA code again. The cookie already cleared all that. Your second factor never gets a chance to do its job.

How they get the cookie

The main tool for this is a nasty category of malware called an infostealer. It’s a small program built to do one thing: grab everything sensitive out of your browser and ship it off to the attacker. Saved passwords, credit card numbers, and yes, all your active session cookies.

People get infected in ordinary ways:

  • A cracked or fake download. Someone grabs a free version of paid software, or a game mod, or a tool from a sketchy site. Bundled inside is the stealer.
  • A fake browser update. A popup says your browser is out of date, click here to update. The download is the malware.
  • A malicious email attachment. The classic. A document that isn’t really a document.
  • A poisoned ad. Some malware rides in through ads on otherwise normal-looking sites.

Once it runs, it takes seconds to scrape your cookies and send them off. Then it’s often gone, deleting itself so you never know it was there. Weeks later, someone logs into your email or your bank from another country, and you have no idea how.

Why this hits businesses hard

An attacker with your session cookie has whatever access you had. If it’s your email cookie, they’re reading your mail, sending as you, and hunting for anything about money or passwords. If it’s your Microsoft 365 or Google Workspace cookie, they may reach your whole company’s files. If it’s your banking cookie, well, you can guess.

And the reason this stings so much is that it defeats the exact protection everyone tells you to turn on. You did the responsible thing and enabled MFA. This attack sidesteps it, because it doesn’t attack the login at all. It steals the pass you already earned.

What this means for you

MFA is still absolutely worth having. It stops a huge range of attacks, and you should keep it on everywhere. But it’s not a force field. You need a couple more layers.

Keep the malware off the machine in the first place

This whole attack starts with an infection. Cut off the infection and you cut off the attack. That means:

  • No cracked software, ever. The ‘free’ version of a paid program is the single most common way stealers get in.
  • Real endpoint protection on every business computer, not just the free antivirus that came with Windows. Something that catches these stealers before they run.
  • Updates from the actual source. Your browser updates itself. Any popup telling you to update it is a lie.

Sign out of the important stuff

A session cookie only works while the session is alive. When you actually log out of a site, you invalidate the wristband. For your most sensitive accounts, banking, payroll, admin panels, get in the habit of logging out when you’re done instead of leaving them open forever. It’s a small friction that shortens the window an attacker has.

Watch for the tell-tale signs

The big one is a login alert from a place you’ve never been. If your email or Microsoft account emails you about a sign-in from another state or country, take it seriously. Don’t ignore it. Change your password immediately, which kills existing sessions, and turn on MFA if it somehow wasn’t already.

Use accounts that support session monitoring

Business platforms like Microsoft 365 can flag and cut off suspicious sessions automatically, ending a hijacked cookie the moment it looks wrong. Turning those protections on is exactly the kind of thing that gets missed when nobody’s managing your setup, and it’s exactly the kind of thing we turn on for clients on day one.

The takeaway

Passwords and MFA guard the front door. Session hijacking climbs through a side window using a key you already used. The fix isn’t to abandon MFA, it’s to keep the malware that steals cookies off your machines in the first place, and to have someone watching for the logins that don’t add up.

If you’re not sure your business computers have real protection against this, or nobody’s watching for strange logins on your accounts, that’s a gap worth closing before it costs you. Reach out and we’ll take a look at your setup. Always happy to troubleshoot.