Join our Newsletter — 33% off our NHI Course
Home FAQ Architecture & Implementation What are the signs that phishing controls are…
Architecture & Implementation

What are the signs that phishing controls are failing against modern adversary-in-the-middle attacks?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 1, 2026 Domain: Architecture & Implementation

The clearest signs are when malicious pages still reach users even though security tools inspected the link, when sandboxing returns a benign page, and when attackers are able to rotate URLs, domains, and visual elements faster than blocklists update. If detections depend on static indicators or remote inspection alone, the control is already trailing the attack.

Why Phishing Defences Break First Against AiTM

Modern adversary-in-the-middle attacks defeat phishing controls by staying interactive. The user still sees a convincing login page, the security stack may inspect the URL or sandbox a harmless response, and the attacker captures the session token after the victim authenticates. That is why page reputation, attachment scanning, and static blocklists often miss the real event: credential relay and session hijacking, not just lure delivery. Current guidance suggests defenders should treat “link inspected” as incomplete assurance when the page can change between inspection and click. NHIMG’s 52 NHI Breaches Analysis and the MITRE ATLAS adversarial AI threat matrix both reinforce the same operational reality: control failure often shows up as successful token theft, not obvious malware. In practice, many security teams discover the gap only after a valid session has already been replayed from an attacker-controlled endpoint.

How It Works in Practice

AiTM kits interpose a proxy between the victim and the legitimate service. That proxy relays usernames, passwords, MFA prompts, and session cookies in real time, so the attacker never needs to crack the password outright. This breaks controls that rely on static indicators because the malicious infrastructure can rotate domains, certificates, and page assets faster than reputation feeds update. It also weakens sandbox-based inspection, because the sandbox may fetch a benign pre-auth page while the live victim session receives the proxied lure.

Security teams should look for behavioural signals instead of only content signals:

  • Authentication succeeds from unusual geographies or impossible travel patterns shortly after a user clicks a message.
  • MFA is approved, yet the session is immediately reused from a different device fingerprint.
  • Users report repeated prompts, page reloads, or “wrong password” loops that indicate token relay.
  • EDR, email gateway, and web proxy logs show the link was inspected, but identity telemetry shows abnormal session creation.

In this workflow, real-time identity and session controls matter more than pre-click URL verdicts. NIST SP 800-53 Rev. 5 emphasises continuous monitoring and access enforcement, while the CISA cyber threat advisories and NHIMG’s CoPhish OAuth Token Theft via Copilot Studio illustrate how quickly token theft can bypass traditional email-centric detections. These controls tend to break down when the organisation still trusts a “clean” pre-delivery verdict as proof that the live authentication flow is safe.

Common Variations and Edge Cases

Tighter phishing controls often increase user friction and analyst workload, so organisations have to balance faster detection against more false positives. That tradeoff is especially visible when the attack uses legitimate cloud login pages or proxy infrastructure that resembles normal business traffic.

There is no universal standard for this yet, but current guidance suggests treating the following as signs of control failure rather than isolated noise:

  • Repeated success by one-time links or QR-based sign-in flows that bypass normal inspection.
  • High-confidence safe verdicts followed by immediate account takeover activity.
  • Session cookie theft that survives MFA, showing the control only protected the password step.
  • Users clicking from trusted mail clients while the attacker injects the malicious page after the first request.

Teams should also watch for gaps between email security and identity security. If the mail gateway is tuned to block known lures but identity telemetry is not being correlated in real time, the attack will look “contained” until the account starts issuing access tokens or API calls. The most reliable signal is not whether the link was scanned, but whether the authentication session behaved normally after the click. Where organisations depend on static URL reputation and delayed sandbox verdicts alone, AiTM attackers can stay ahead of the control stack.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10N/AAiTM token relay mirrors agent-style session abuse and dynamic execution paths.
CSA MAESTRON/AMAESTRO covers runtime trust, identity, and session protection for modern workflows.
NIST AI RMFGOVERNAI RMF governance supports accountability for adaptive, fast-changing attack detection.
NIST CSF 2.0DE.CM-1Continuous monitoring is directly relevant when static phishing controls miss live abuse.
NIST Zero Trust (SP 800-207)PR.AC-7Zero trust requires ongoing verification, which AiTM specifically tries to bypass.

Establish ownership, monitoring, and escalation paths for adaptive phishing and session theft risks.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 1, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org