Multi-factor authentication (MFA) is a strong lock on the front door. But it's not the only thing that determines whether someone can access your systems.
At AWSMTECH (Switzerland) LTD, we regularly explain to small businesses in Geneva that what happens after login matters just as much as the login itself.
Once logged in, your browser keeps you authenticated through a session token, often stored as a cookie. Think of it as a wristband at an event. Once security has let you in, that wristband proves you're allowed to be there. If an attacker steals that wristband, they may no longer need to pass the MFA check.
This is the very principle of session cookie hijacking.
The attacker doesn't break MFA. They bypass it by reusing your already-authenticated session.
This is not a reason to stop using MFA. It's a reason to stop treating MFA as the finish line.
For businesses across French-speaking Switzerland, the real defence relies more on multi-layered controls: phishing-resistant authentication, healthy and managed devices, stricter session policies, and monitoring capable of quickly detecting suspicious access.
01Why MFA is not a "game over" protection
MFA remains one of the most effective security improvements organisations can implement, and AWSMTECH (Switzerland) LTD strongly recommends it to all its clients in Geneva. However, MFA alone does not end an attack.
The reason is simple: attackers don't always try to break the login itself. They bypass it.
Cloudflare notes that "attackers are finding new ways to bypass MFA" and that modern incidents rarely rely on a single technique. They generally form part of chained attacks, where one method paves the way for another.
MFA blocks a large share of credential theft. What it doesn't automatically protect against is what happens after a successful login.
This is precisely where session cookie hijacking comes in.
Microsoft has described adversary-in-the-middle phishing campaigns in which attackers use proxy sites to intercept both the user's credentials and the session cookie proving that an authenticated session exists.
This is not a weakness of MFA. The attacker doesn't break MFA: they simply reuse the session once MFA has already been validated.
02What a session cookie is — and why attackers want it
When you log in to a web application, the service needs a way to remember that you have already proven your identity. This temporary authenticated state is called a session.
Session credentials are typically stored as cookies. Kaspersky explains that session hijacking is often called "cookie hijacking" for this exact reason.
Attackers target session cookies because they represent a shortcut.
Proofpoint describes session tokens as "digital keys" that let users stay authenticated. If these keys are stolen, attackers can impersonate legitimate users and potentially bypass controls such as MFA.
This is what makes session cookie hijacking so effective.
If an attacker manages to capture the cookie representing your active session, they don't need to break the login process. They simply reuse what you've already validated and gain access to the same applications and data — exactly as if they were sitting at your keyboard.
03How session cookie hijacking actually works
Many teams picture account takeover as a password-guessing or MFA-fatigue attack. Session hijacking works differently.
The attacker's goal is not to log in as you. They seek to obtain proof that you are already logged in and reuse it, often without triggering a new authentication request.
1) Adversary-in-the-middle (AiTM) phishing
AiTM phishing is a classic login-proxy trap.
You believe you're logging into a legitimate site, but you're actually interacting with a fake page controlled by the attacker. This page relays the login in real time to the real service, which makes everything look perfectly normal, including MFA.
Attackers use this technique to intercept the username, password and the session cookie that proves authentication. Once again, MFA is not broken. MFA works, and then the session is stolen immediately afterward.
One known campaign attempted to target more than 10,000 organisations, showing just how scalable and effective this technique has become.
2) Browser-in-the-Middle (BitM) session theft
Browser-in-the-middle attacks go even further.
Instead of simply relaying the login, the attacker retains control of the user's own browsing session. Google's Threat Intelligence team explains that stealing a session token is practically equivalent to stealing the authenticated session — and once obtained, the attacker no longer needs to pass an MFA challenge.
In this scenario, the attacker does not attempt to authenticate as the user. They take advantage of the session after authentication has already occurred.
3) Cookie theft directly from the workstation
Not all session hijacking relies on sophisticated phishing infrastructure.
In some cases, attackers steal session data directly from a compromised device. If malware gains access to a workstation, it can extract session cookies and reuse them elsewhere.
Session tokens function as digital keys. If retrieved from an infected device, they can allow attackers to impersonate legitimate users and access sensitive systems without ever going through the login page.
04MFA is a foundation — not the finish line
MFA remains essential. It blocks a huge category of credential-based attacks and significantly raises the bar for attackers. But session cookie hijacking is a reminder that not every attack targets the login step.
For SMEs based in Geneva, the practical response must be layered and realistic, without falling into alarmism:
- Make phishing harder through phishing-resistant logins
- Treat device health and updates as part of identity security
- Strengthen session behaviour on sensitive applications
- Monitor suspicious access patterns indicating session reuse
When these controls work together, MFA stops being a mere reassuring checkbox and becomes what it was always meant to be: a solid foundation, backed by protections around the session itself.
At AWSMTECH (Switzerland) LTD, we help small and medium-sized businesses across Geneva and French-speaking Switzerland design identity protections aligned with how modern attacks actually work.
Contact us today if you'd like to protect your login sessions against hijacking.
Need IT support?
AWSMTECH (Switzerland) LTD supports SMEs in Geneva and French-speaking Switzerland with pragmatic, risk-oriented audits.
Contact us
