Remove Business Email Compromise Remove MFA Remove User Authentication
article thumbnail

Adversary-in-the-middle fraud: A growing concern for payments providers in 2025

The Payments Association

When the victim enters their credentials, the attacker captures these details and may steal session cookies to bypass multifactor authentication (MFA). Using stolen session cookies, the attacker can authenticate themselves into the victim’s account, gaining unauthorised access to emails or other resources.