Skip to main content

Aug 11, 2026

The Attacker Who Never Logged In

Stolen session tokens skip the login entirely, so the alerts built around sign-ins never fire

Everyone watches the login. Conditional access checks the device, MFA challenges the user, impossible-travel rules flag the geography. It is the most instrumented moment in identity security, and a whole class of attack never triggers it.

Session tokens are the reason. When an attacker steals a valid session cookie, through malware, a phishing proxy, or a compromised endpoint, they replay it and inherit an authenticated session. No password, no MFA prompt, no login event to inspect. To every sign-in-based control, nothing happened.

What the Token Can't Carry

A stolen session grants access, but it carries none of the behavior that comes with the real user. The attacker holds the key without knowing how the person actually uses it: which files they open first, the cadence of their day, the systems they never touch. That is where the impersonation shows.

Baseline the Session, Not Just the Sign-In

PeopleBase profiles how each identity actually uses its access. A replayed token that starts pulling from repositories the real user has never opened, at hours they never work, breaks that profile even when authentication looks perfect. No signature required, because the tell lives in the usage, not the login.

The strongest front door doesn't help if the attacker is already inside holding a key. The question is what they do next.

See the latest from Abnormal's product and engineering teams.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.