Cybersecurity Glossary

Session Hijacking

Stealing the token that keeps you logged in, so the attacker skips the password and the second factor entirely.

What Session Hijacking means

After you sign in, the service issues a session token that your browser presents on every request. If an attacker steals that token, through malware on the device or a malicious script on a page, they are logged in as you. No password prompt and no second factor appears, because the login already happened.

Why Session Hijacking matters for small businesses and nonprofits

This is how attackers increasingly bypass multi factor authentication. It makes device health matter as much as password strength, because a compromised laptop leaks tokens no matter how good the login process was.

What to do about Session Hijacking

Three steps to deal with Session Hijacking

  • Set shorter session lifetimes for administrative accounts
  • Require managed, compliant devices for access to sensitive systems
  • Sign out and revoke all sessions when a device is lost or a compromise is suspected

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.