Session hijacking is the takeover of an authenticated online session by someone who has obtained the token proving that a user has already logged in. Websites issue that token, usually a cookie, so people do not have to re-enter a password on every page. Whoever holds a valid copy is, as far as the server can tell, the account owner. The attacker skips the login page entirely, and with it the password check, the one-time code and most of the alarms tied to sign-in.

OWASP, the open web security foundation, describes the attack as compromising "the session token by stealing or predicting a valid session token". MITRE's ATT&CK framework catalogues the theft as technique T1539 and the reuse of the stolen value, often called "pass-the-cookie", as T1550.004.

How a session is taken

HTTP has no memory between requests. After a successful login the server sends the browser a random identifier in a Set-Cookie header, and the browser returns it with every later request so the server knows who is asking. Browser vendors use "session cookie" narrowly for a cookie with no expiry date that disappears when the browser closes. Authentication cookies are frequently persistent instead: Chrome has capped any cookie's lifetime at 400 days since version 104 in August 2022, and "stay signed in" settings routinely run for weeks.

OWASP lists five ways the token leaks: a predictable identifier, sniffing it on the network, client-side attacks such as cross-site scripting (XSS), man-in-the-middle interception and man-in-the-browser malware. Three dominate in practice.

Infostealer malware is the largest source. A victim runs a disguised file, often a fake software crack, invoice or sponsorship brief, which copies cookie stores and saved passwords from every browser on the machine and uploads them. Kristian Monsen of Chrome's counter-abuse team wrote in April 2024 that "the stolen cookies continue to work even after the malware is detected and removed". NordStellar, a threat exposure unit of Nord Security, counted nearly 94 billion stolen cookies in Telegram channels where criminals advertise stolen data in April 2025, up from about 54 billion a year earlier, and found 20.55% still active.

Adversary-in-the-middle (AiTM) phishing steals the token in transit. Instead of a static fake login page, the attacker runs a reverse proxy that relays traffic between victim and real site, so the victim completes a genuine login, including the second factor, and the proxy keeps the resulting cookie. The technique is the account-level version of the man-in-the-middle position MITRE tracks as T1557. Microsoft reported on July 12, 2022 that one campaign built on the open-source Evilginx2 kit had targeted more than 10,000 organisations since September 2021, and that attackers launched payment fraud "as little as five minutes" after stealing a session.

Network sniffing, the oldest route, reads cookies sent unencrypted; near-universal HTTPS has made it rare.

The attacker then imports the token into a browser, often an anti-detect browser that mimics the victim's device fingerprint. On the server side, sites set the HttpOnly attribute so scripts cannot read a cookie, Secure so it travels only over HTTPS, and SameSite to limit cross-site sending; they rotate identifiers after login, shorten lifetimes and flag sessions that suddenly change country or device. Chrome 140 added the __Http and __HostHttp cookie prefixes in August 2025 so servers can tell whether a cookie was set by a server response or by a script.

The idea predates the web: a 1985 Bell Labs report by Robert T. Morris showed how predictable TCP sequence numbers let a remote host impersonate a trusted one.

Web session hijacking became a public issue on October 24, 2010, when Seattle developer Eric Butler released Firesheep, a Firefox add-on, at the ToorCon conference in San Diego. Many large sites encrypted the login page but then sent the session cookie in clear text. On open Wi-Fi, Butler said, "cookies are basically shouted through the air". Firesheep listed nearby users of Facebook, Twitter, Amazon and other sites; a double-click logged the operator in as them. Computerworld counted nearly 50,000 downloads within days. The episode pushed large sites towards encrypting every page.

Encryption closed the network route, so attackers moved to the endpoint. Google's Threat Analysis Group reported on October 20, 2021 that a cluster of actors had hijacked YouTube creators' channels since late 2019 with cookie-stealing malware delivered through fake sponsorship offers. The group identified about 15,000 attacker accounts and at least 1,011 malware domains; hijacked channels sold for between $3 and $4,000 depending on subscriber count. WithSecure documented Ducktail, a Vietnam-linked operation using browser cookies to take over Facebook Business accounts, on July 26, 2022.

Why it matters for marketers

Advertising accounts combine stored payment methods and a trusted spending history, which gives them resale value. Mimecast's threat research team, in a July 28, 2026 analysis, counted 6.4 million detections of ad-account theft activity over four years and listed aged Google Ads accounts for high-risk verticals at $200 to $270 on Telegram. Sellers supply "cookie-login" instructions for entering stolen sessions without triggering checkpoints. Attackers then add their own administrators, demote the owner and spend against the victim's card.

Browser extensions are another vector. On December 25, 2024, a malicious update to the Cyberhaven Chrome extension, pushed after an administrator was phished, collected authenticated sessions and cookies with a focus on Facebook advertising accounts, according to an analysis by Expel.

Creators face the same economics. YouTube released a recovery tool for hacked creator accounts on July 8, 2025, first securing the linked Google Account and then reversing channel changes. Agencies have meanwhile reported fake client leads designed to obtain manager account access, a social-engineering route to the same outcome.

Where the defences fall short

Multi-factor authentication (MFA) protects the login, not the session that follows. Microsoft stressed in 2022 that AiTM is "not a vulnerability in MFA": the stolen cookie already carries the MFA claim. Cloudflare's first threat report, published on March 3, 2026, listed session token theft through infostealers such as LummaC2 among its eight main trends.

Passkeys, cryptographic credentials bound to a website's domain, defeat AiTM proxies because the browser will not use them on a look-alike domain. They do nothing against an infostealer that copies a cookie issued after a legitimate passkey login. That gap explains why Google Ads began requiring a passkey for sensitive actions such as user access changes from July 15, 2026, rather than only at sign-in: a hijacker riding a stolen session still cannot add an administrator without the owner's device.

Browser-side protections have been bypassed quickly. Chrome 127 introduced app-bound encryption on Windows in July 2024. By late September, according to Risky Business, developers of Lumma, Vidar, Meduza, WhiteSnake and Lumar stealers were telling customers they had a workaround. Protections also vary by browser: Microsoft Edge decrypts every saved password into memory at launch, a disclosure from April 29, 2026 that Microsoft called "by design".

Detection, the fallback MITRE recommends through signals such as impossible travel, relies on heuristics that VPN use and travelling staff can confuse. Mimecast also argued that no equivalent of card-fraud chargeback protection exists for hijacked ad spend.

Not the same as

Session replay records a visitor's clicks, scrolls and form entries so a site owner can watch them back, using tools such as Microsoft Clarity or Hotjar. It is an analytics practice, regulated as a privacy matter; France's CNIL opened a consultation on it in February 2026. It does not transfer control of an account.

Credential stuffing tests leaked username and password pairs against many sites at once. It attacks the login step that session hijacking bypasses, and is blunted by MFA in a way hijacking is not.

Cookie syncing maps one ad tech company's cookie ID to another's for the same browser so a buyer can recognise users in bid requests. It moves pseudonymous advertising identifiers, not authentication tokens, and grants no account access. Affiliate "cookie theft", meanwhile, refers to overwriting attribution cookies to divert commission, the practice at the centre of the Honey dispute.

Recent developments

Google made Device Bound Session Credentials (DBSC) generally available to Windows users in Chrome 146, announced on April 9, 2026, with macOS support due in a later release. Under DBSC, the browser generates a key pair at login and stores the private key in the device's Trusted Platform Module. The server then issues short-lived cookies, around 10 minutes in Chrome's documentation example, that can be renewed only by signing a challenge with that key. A copied cookie expires before it is useful. Google said it observed "a significant reduction in session theft" during testing but published no figures, and conceded that "there is no reliable way to prevent cookie exfiltration using software alone on any operating system". DBSC is progressing through the W3C Web Application Security Working Group with Microsoft as design partner. It protects only sites that implement it, on devices with secure key storage.

Advertising platforms are adding friction after login. Google Ads API v24.1 added a passkey_enabled field on May 13, 2026, passkeys became mandatory for new API refresh tokens from August 5, 2026, and the interface began requiring a second administrator to approve access removals in July. The W3C published WebAuthn Level 3 as a Recommendation on August 25, 2026.

The token problem extends beyond browsers: stolen Drift OAuth tokens gave attackers Salesforce access across hundreds of companies in August 2025. AI agents that operate inside a user's logged-in session have prompted a legal question of their own: a federal court barred Perplexity's Comet browser from Amazon accounts on March 9, 2026, finding that user permission did not equal Amazon's authorisation.

Timeline

  • 1985 - Robert T. Morris's Bell Labs report describes TCP sequence-number prediction, an early network session hijacking technique.
  • August 2007 - RFC 4949 gives man-in-the-middle attacks a reference definition.
  • October 24, 2010 - Eric Butler releases Firesheep at ToorCon in San Diego; nearly 50,000 downloads follow within days.
  • October 8, 2019 - MITRE adds T1539, Steal Web Session Cookie, to ATT&CK.
  • Late 2019 - Cookie-theft campaigns against YouTube creators begin, according to Google.
  • September 2021 - Start of the Evilginx2-based AiTM campaign later reported by Microsoft.
  • October 20, 2021 - Google's Threat Analysis Group publishes its YouTube cookie-theft findings.
  • July 12, 2022 - Microsoft reports AiTM phishing against more than 10,000 organisations.
  • July 26, 2022 - WithSecure documents Ducktail targeting Facebook Business accounts.
  • August 2022 - Chrome 104 caps cookie lifetimes at 400 days.
  • April 2, 2024 - Google announces the Device Bound Session Credentials prototype.
  • July 2024 - Chrome 127 introduces app-bound encryption for cookies on Windows.
  • September 2024 - Infostealer developers claim app-bound encryption bypasses.
  • December 25, 2024 - Malicious Cyberhaven extension update targets Facebook advertising sessions.
  • April 2025 - DBSC origin trial opens in Chrome 135.
  • May 2025 - Microsoft-led action disrupts Lumma Stealer, seizing about 2,300 domains after more than 394,000 infections in two months.
  • June 5, 2025 - NordStellar reports nearly 94 billion stolen cookies.
  • July 8, 2025 - YouTube launches a hacked-account recovery tool for creators.
  • August 2025 - Chrome 140 beta adds __Http and __HostHttp cookie prefixes; Drift OAuth tokens are stolen.
  • March 3, 2026 - Cloudflare's first threat report flags session token theft.
  • April 9, 2026 - DBSC becomes generally available on Windows in Chrome 146.
  • July 15, 2026 - Google Ads requires passkeys for sensitive account actions.
  • July 28, 2026 - Mimecast reports 6.4 million ad-account theft detections over four years.
  • August 5, 2026 - Passkeys required for new Google Ads API refresh tokens.
  • August 25, 2026 - WebAuthn Level 3 becomes a W3C Recommendation.

Summary

Who. Attackers range from commodity infostealer operators and phishing-kit users to organised groups selling hijacked YouTube channels and advertising accounts. Defences come from browser makers such as Google and Microsoft, standards bodies including the W3C and OWASP, and platforms such as Google Ads, YouTube and Meta.

What. Session hijacking is the use of a stolen or predicted session token, usually an authentication cookie, to act as a logged-in user without the password or second factor.

When. Network-level hijacking was described in 1985 and web cookie hijacking was popularised by Firesheep in October 2010. Infostealer-driven cookie theft has dominated since about 2019, and Chrome's device-bound session credentials reached general availability on Windows on April 9, 2026.

Where. Theft happens on infected computers, on proxy phishing sites and through compromised browser extensions; the stolen sessions are traded on Telegram channels and criminal forums and replayed against any web service, including advertising and creator platforms.

Why. Sessions exist so users need not log in on every request, which makes a valid token as powerful as the account itself. Because the theft happens after login, MFA and passkeys alone do not stop it, which is why defences are shifting towards binding sessions to hardware and adding checks at sensitive actions.