TL;DR: Man-in-the-middle attacks are now aimed at browsers, APIs, device enrollments, DNS, and agent-to-agent traffic, with stolen cookies, tokens, and device credentials turning one interception into persistent access, according to Apono. The real control problem is not interception alone, but whether access is short-lived, scoped, and continuously verified.
At a glance
What this is: This article breaks down seven MitM attack patterns and shows how intercepted cookies, tokens, and device credentials can convert transient network interception into durable access.
Why it matters: It matters to IAM and NHI practitioners because the weak point is often the standing value of captured credentials, not the interception event itself.
By the numbers:
- Automated cyber threat activity surged 16.7%, with over 1.7 billion stolen credentials circulating on the dark web and fueling a 42% increase in credential-based targeted attacks.
Context
Man-in-the-middle risk is no longer limited to user browsers on untrusted networks. In cloud and distributed systems, the same interception pattern now applies to API calls, device enrollment flows, service-to-service traffic, and emerging agent-to-agent communications, which makes the security problem one of identity governance as much as transport security.
The practical failure is that captured credentials often remain valid after interception. When tokens, cookies, certs, or service credentials are long-lived or overprivileged, an attacker can turn a brief network position into persistent access. That is why MitM now sits squarely in NHI governance, secrets management, and session control rather than only in network security.
Key questions
Q: What breaks when machine credentials stay valid after a MitM intercept?
A: The control that breaks is trust in the credential itself. If a token, cookie, or service account secret remains valid after interception, the attacker can replay it from elsewhere and inherit the original access scope. Short expiry, binding, and rapid revocation are what stop a transient intercept from becoming persistent impersonation.
Q: Why do intercepted service tokens create higher risk than intercepted user passwords?
A: Because service tokens often carry broader scope, longer lifetimes, and fewer behavioural checks than a human login. A captured token can unlock automated workflows, APIs, or storage paths without MFA prompts or user awareness. The risk is not the credential type alone, but the combination of privilege, replayability, and weak lifecycle control.
Q: What are the signs that MitM controls are failing in cloud and API traffic?
A: Look for reused tokens, impossible travel patterns, concurrent sessions, unexpected certificate warnings, and traffic that succeeds from endpoints that should not satisfy the original context. In machine identity environments, any long-lived credential that can still operate after a network intercept is evidence that the control boundary is too loose.
Q: Should teams prioritise zero standing privilege or token rotation first for MitM defence?
A: Prioritise the control that removes reusable access fastest in your environment. If long-lived secrets and standing roles are the main exposure, zero standing privilege usually delivers more immediate reduction than rotation alone. If captured tokens are already short-lived, focus next on binding, provenance, and revocation speed.
Technical breakdown
How MitM turns intercepted sessions into usable identity
MitM attacks work by inserting an attacker into the communication path so traffic can be observed, altered, or replayed. In modern environments, the value is not just in reading data in transit. The real prize is the identity artefact inside the session: cookies, bearer tokens, API keys, device certificates, or enrollment credentials. Once copied, those artefacts can be reused outside the original network path unless they are bound to device, context, or a very short validity window. That makes session design an identity-control problem, not just a transport-encryption problem.
Practical implication: Treat intercepted credentials as an identity lifecycle issue and shorten the period in which any captured token can be reused.
Why machine identities amplify MitM blast radius
Machine identities multiply the impact of interception because they are often deployed at scale, reused across services, and granted broader access than a human session would justify. A stolen service token or agent credential can expose not just one user action, but an entire workload, API path, or automation flow. This is where standing privilege becomes dangerous: if the credential is both broadly scoped and long-lived, MitM does not need to break encryption to be effective. It only needs one successful capture. The result is a large blast radius from a single interception event.
Practical implication: Inventory NHI credentials by scope and lifetime, then remove standing access where a replayable token would expose multiple systems.
Agent-to-agent traffic needs provenance, not trust by default
Agent traffic introduces a new MitM surface because cooperating software entities may accept instructions, telemetry, or tool calls without strong proof of origin. When an attacker can impersonate a service or insert a proxy into the exchange, the risk is not just data theft. It is workflow hijack, where the attacker alters commands, poisons context, or triggers downstream actions that look legitimate. That is why mutual authentication, signing, and replay protection matter. In agentic and machine-to-machine flows, the protocol must prove who sent the request and whether it was altered in transit.
Practical implication: Require request provenance controls for machine and agent communication so intercepted traffic cannot be replayed as trusted work.
Threat narrative
Attacker objective: The attacker aims to convert a temporary interception into durable impersonation of users, services, or agents with access that outlives the original network position.
- Entry occurs when an attacker positions themselves between parties or compromises a network path, certificate trust, DNS route, or rogue access point that carries legitimate traffic.
- Credential capture follows when cookies, tokens, API keys, or device credentials are observed or replayed from that traffic stream.
- Escalation happens when the stolen credential is valid outside the interception path and can be used to impersonate a user, workload, or agent with standing scope.
- Impact is persistent access to systems, data, or automation flows because the captured identity artefact remains trusted after the original session ends.
Breaches seen in the wild
- tj-actions/changed-files compromise 2025: A stolen bot token let attackers poison tj-actions/changed-files so pipelines printed their CI/CD secrets to public logs (CVE-2025-30066).
- Secrets in VS Code extensions 2025: Wiz found 550+ secrets in VS Code extensions, including publishing tokens able to push malicious updates to about 150,000 installs.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Short-lived access, not interception resistance, is the decisive control variable: MitM succeeds when the captured artefact keeps working after the attacker leaves the network path. That means token lifetime, replay resistance, and scope matter more than the interception event itself. The governance lesson is that access must decay faster than an attacker can operationalise it, otherwise the control plane is still handing out usable trust.
Machine identity governance is now a MitM control domain: Service accounts, workloads, and agents are not peripheral to this attack pattern. They are the preferred target because they often carry higher privilege and weaker behavioural scrutiny than human sessions. The implication for practitioners is to govern machine identity as a first-class access tier, not as an operational byproduct of infrastructure.
Standards that assume session durability need rethinking for NHI traffic: Controls built around reviewable, stable sessions fit human identity better than ephemeral machine exchanges. A token that can be captured and replayed between automated systems creates a governance gap because the identity artefact can be exercised without any user interaction. Practitioners should treat per-call authorization and device-bound proof as baseline expectations for high-value NHI pathways.
Agent traffic introduces a trust boundary that traditional network security does not fully cover: When software entities exchange instructions, telemetry, or tool calls, the attack is no longer only eavesdropping. It becomes request substitution and workflow manipulation. The named concept here is intercepted identity persistence: a captured token or credential remains authoritative long enough to drive downstream action. Security teams need to recognise that persistence begins at the credential layer, not after compromise is detected.
Zero Standing Privilege is the practical response pattern, but the deeper issue is identity decay: The article shows that intercepted credentials are dangerous because they stay valid. That means the core governance failure is the absence of timely expiry, revocation, and scoped issuance across machine and agent identities. The practitioner conclusion is clear: if a credential can survive the session in which it was captured, MitM has already won part of the battle.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Static vs Dynamic Secrets
What this signals
Interception is now an identity problem: The practical boundary has moved from packet inspection to credential governance. If the captured artefact still works after the attacker exits the network path, the organisation has an identity lifecycle failure, not just a transport-security gap.
Intercepted identity persistence: This is the pattern practitioners should watch for when tokens, cookies, and service credentials outlive the session in which they were captured. The fix is not only encryption at rest or in transit, but shortening the period in which a stolen identity artefact remains authoritative.
Machine identities expose a larger attack surface because many organisations expose NHIs to third parties, according to the Ultimate Guide to NHIs. That makes scoped issuance, revocation, and per-call verification central to reducing MitM blast radius.
For practitioners
- Shorten token lifetime and scope Issue machine and user tokens with the narrowest feasible permissions and the shortest workable validity window so captured credentials expire before they can be replayed.
- Bind high-value sessions to device and context Use device-bound authentication, certificate binding, and contextual checks so a replayed token is not enough to authenticate from a different endpoint or network path.
- Require mutual authentication for service traffic Mandate mTLS, signed requests, and replay protection for API calls, agent links, and other machine-to-machine exchanges to block silent request substitution.
- Remove standing privilege from NHI pathways Replace long-lived service credentials with just-in-time access and per-call authorisation so a stolen secret does not expose an always-on trust path.
- Tighten DNS and certificate trust controls Monitor registrar accounts, DNS changes, and certificate issuance so attackers cannot redirect traffic or exploit fraudulent certificates to stage interception.
Key takeaways
- MitM attacks now succeed by turning captured cookies, tokens, and credentials into durable access across browsers, APIs, machine identities, and agent traffic.
- The article ties the problem to scale, citing 16.7% growth in automated threat activity, 1.7 billion stolen credentials on the dark web, and a 42% rise in credential-based targeted attacks.
- The control that matters most is not whether interception is possible, but whether access decays quickly enough that the stolen identity artefact becomes useless.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | Captured cookies, tokens, and credentials are the core MitM payload in this article. |
| NHI-04 — Insecure Authentication | The article shows how weak trust validation lets intercepted identities be impersonated. | |
| NHI-05 — Overprivileged NHI | Overprivileged service accounts and tokens increase the blast radius of a single MitM capture. | |
| Recommendation — Scan for exposed NHI secrets and remove any credentials that can be replayed after interception. Enforce stronger authentication patterns so replayed machine credentials cannot pass as legitimate access. Reduce privilege scope for NHI credentials so intercepted access cannot reach unrelated systems. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The attack patterns described pivot from credential capture to broader environment access. |
| Recommendation — Map MitM findings to credential access and lateral movement to prioritise detection and containment. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article repeatedly hinges on whether captured access remains authorised after interception. |
| Recommendation — Apply entitlement controls so intercepted credentials cannot retain broad or persistent authorisation. | ||
Key terms
- Man-in-the-Middle Attack: A man-in-the-middle attack is an interception technique where an attacker positions themselves between two parties that believe they are communicating directly. The attacker can read, alter, or replay traffic, which makes the attack especially dangerous when credentials, sessions, or certificates are involved.
- Machine Identity: The digital identity of a machine, device, or workload, such as a server, container, or VM, used to authenticate it within a network. Sometimes used interchangeably with NHI, though NHI is the broader category.
- Token Replay: Token replay is the reuse of a valid access or refresh token by someone other than the intended client. The token may still be unexpired and cryptographically correct, so the compromise often shows up only through context anomalies such as location, device, or session overlap.
- Zero Standing Privilege: A control model in which an identity does not keep persistent access unless it is actively needed. For NHIs, this means credentials and permissions are issued for a narrow task and then removed. It reduces the time window and reuse value of stolen access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org