Session token theft is an attack in which criminals steal the digital proof that you have already signed in, so they can enter your Microsoft 365 account without a password or a second factor. After a successful login, the identity provider issues access and refresh tokens and your browser stores a session cookie. Anyone who holds those artifacts is treated as you until they expire or are revoked.
This is now the dominant way attackers get past multi-factor authentication (MFA). Security researchers tracking September 2026 campaigns describe a wave of phishing that abuses legitimate Microsoft sign-in flows rather than fake password boxes. A campaign dubbed CSuite combines Microsoft 365 session theft with remote monitoring tools such as ScreenConnect, Action1, Atera, Syncro and PDQ Connect, with sandbox data showing about half of submissions coming from the United States. Another, N0va, uses device code phishing to collect tokens from users in North America and Europe while impersonating Teams, SharePoint, OneDrive, DocuSign and Zoom.
For IT managers and CIOs, the lesson is simple: MFA alone is no longer proof that the person is who they claim to be. A stolen session skips the prompt entirely. Protecting identity now means protecting the session, the device and the network path around it, which is the core of a modern cybersecurity program.
Why does MFA fail against these attacks? Because the attacker never has to defeat it. Two techniques dominate.
The first is adversary-in-the-middle (AiTM) phishing. The victim clicks a link to a look-alike page that proxies the real Microsoft sign-in in real time. The user types the password, approves the MFA prompt and lands on a normal mailbox, while the proxy quietly copies the session cookie. The second is device code phishing. The attacker starts a genuine device-authorization request, then persuades the victim to enter a short code on the real microsoft.com/devicelogin page, often under the pretext of a shared document or a Teams meeting. The victim completes MFA on the legitimate site and, in doing so, hands the attacker valid tokens.
Both methods are hard to spot because every page the user sees is either real or a perfect relay, and every log entry shows a successful, MFA-verified sign-in. Attackers then use the access to read email, create inbox rules, register their own devices and deploy remote access software for persistence, a pattern that often ends in fraud or ransomware.
For organizations in Latin America and the US that rely on single sign-on across email, files and Teams, one stolen session can expose the entire workspace within minutes.
How do you stop token theft in practice? Treat it as a layered identity and network problem rather than a single product.
Each layer removes an option the attacker needs, so a single failure no longer becomes a breach.
Why do enterprises need to act now? Because the business impact of a stolen session is larger than a stolen password. A single token can expose mailboxes, SharePoint libraries and Teams conversations, and it can be used to impersonate an executive in a payment request.
Closing this gap delivers measurable value. Lower fraud and ransomware risk, since attackers lose the foothold they need to move laterally. Faster response, because centralized monitoring and automated session revocation cut dwell time. Regulatory confidence, as evidence of strong authentication, conditional access and incident records supports compliance with LGPD in Brazil, Colombia's Law 1581 and US state privacy rules, and it helps at cyber-insurance renewal. Better user experience, because passkeys and security keys are usually faster than typing codes.
Network design matters too. Traffic from remote and branch users should be inspected consistently, whether it reaches the cloud through the office or straight from home. Combining identity controls with multi-operator connectivity and SD-WAN gives IT teams one predictable, secured path to Microsoft 365 and other cloud services, and keeps collaboration tools such as Microsoft Teams telephony available and protected.
What should a CIO ask their team this week? Three questions expose most of the risk. Is device code flow blocked by Conditional Access for users who do not need it? Which remote monitoring tools are approved, and would we notice an unapproved one? How long does it take us to revoke every active session for a suspicious identity? If any answer is unknown, the organization is relying on luck. Measuring these times, and rehearsing them in a tabletop exercise, turns identity security from a checkbox into a capability that leadership, auditors and insurers can verify.
HIT Communications has spent more than 30 years operating enterprise telecom and IT services across Latin America, the United States and Europe. That experience means one team can look at the whole picture: the identity provider, the endpoint, the network and the voice and collaboration platforms that attackers try to reach.
Our security services include managed SOC, SIEM and MDR monitoring around the clock, zero trust design, conditional access hardening for Microsoft 365, and incident response playbooks that include session revocation and device isolation. On the infrastructure side, our IT managed services, cloud backup and multi-operator connectivity keep your business running while controls are tightened, and our Microsoft Teams Direct Routing and cloud PBX services keep voice on the same secure foundation.
If you are unsure how exposed your tenant is to device code phishing or AiTM attacks, we can review your Conditional Access policies, RMM inventory and monitoring coverage and give you a prioritized remediation plan. Learn more about our IT managed services and how we operate in your region.
Session token theft and device code phishing show that attackers have adapted to MFA. The winning response is to secure the whole session: phishing-resistant authentication, restricted device code flow, trusted-device requirements, controlled remote tools and round-the-clock detection.
Start this week by disabling device code flow where it is not needed, auditing which RMM tools are approved, and enrolling privileged users in FIDO2 keys or passkeys. Then build toward continuous monitoring so a stolen session is caught and revoked before it becomes an incident.
Ready to close the gap? Contact HIT Communications to schedule an identity and session security assessment with our specialists.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch