On the network
The classic form intercepts traffic on a network the attacker controls or can manipulate: a fake WiFi hotspot named after a café or hotel, a compromised router, or techniques such as ARP spoofing on a local network. Encryption with TLS (HTTPS) has made reading traffic much harder, which is why attackers have moved to other methods.
In phishing
Modern phishing kits act as a reverse proxy: the victim sees the real login page of Microsoft 365 or Google, relayed through the attacker's server. The victim enters the password and completes MFA normally, and the attacker captures the session cookie created after login. With that cookie, the attacker can access the account without the password or the second factor, which leads to account takeover.
Defences
MFA that resists phishing, such as passkeys or FIDO2 security keys, is bound to the real website and does not work through a proxy. Conditional access policies can require managed devices or trusted locations and shorten session lifetimes. Alerts on sign ins from unusual infrastructure help detect stolen sessions, and revoking sessions should be part of the response to any suspected compromise.
Everyday precautions
Avoid untrusted public WiFi for work or use a VPN, keep browsers and devices updated, and teach users that a correct looking login page is not proof that it is legitimate. Checking the address bar is still useful, and security awareness training should cover this technique.




