What breaks is the assumption that completing MFA proves the session is trustworthy. In an AiTM attack, the attacker relays the login in real time, captures the session cookie, and can reuse that session without the second factor. Security teams need to treat session replay as the real failure mode, not just password theft.
Why Proxied MFA Stops Proving Session Trust
When MFA is relayed through a reverse proxy, the login ceremony can still complete while the attacker sits in the middle and captures the authenticated session. That means the security boundary shifts from “did the user pass MFA” to “is this session bound to the right device, origin, and trust context?” The practical failure is not factor theft alone, but trust in a session that can be replayed elsewhere.
In a proxy-mediated flow, the attacker does not need to defeat the second factor after the fact. They only need to forward it once, then keep the resulting session artifact. That is why phishing-resistant authentication, session binding, and replay detection matter more than a checkbox view of MFA success.
How an AiTM Proxy Turns Authentication Into Session Theft
An adversary-in-the-middle proxy preserves the appearance of a normal sign-in while silently relaying requests between the victim and the real identity provider. The victim sees a legitimate page, enters credentials, completes MFA, and receives no obvious warning. The proxy then extracts the session cookie or equivalent token and can reuse it without repeating the second factor.
This breaks assumptions in systems that treat MFA completion as proof of ongoing trust. It also weakens downstream controls that only inspect authentication state at login, because the attacker is operating with an already-issued session rather than reauthenticating in a way the user can notice.
What Stops Working After the Cookie Is Stolen
Once the session is replayable, the defender loses the protection that MFA was supposed to provide for the rest of the session lifetime. Conditional access may still help if it reevaluates risk during use, but static trust decisions made at login can be bypassed. The weaker the session binding, the easier it is for the captured token to act like a full sign-in.
That is why the real control question is whether the session can be reused outside the original browser, device, or network context. Controls that make token theft harder, shorten token value, or detect abnormal session reuse are more relevant than authentication success alone.
Risk and Threat Considerations
Proxyable MFA creates a high-confidence path for account takeover because the attacker converts a one-time authentication event into a reusable session. The risk is especially material for remote access, admin portals, and high-value SaaS applications where a valid session can expose mail, data, secrets, or privileged actions.
Failure mechanism: The attacker relays the login in real time, captures the issued session token, and reuses it from a separate location or browser context without needing the second factor again.
Impact: Organizations may believe MFA is protecting the account while an attacker is already acting as the user, which can lead to stealthy persistence, data access, privilege abuse, and delayed detection.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP API Security Top 10 addresses the attack and risk surface, while NIST SP 800-63, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP API Security Top 10 | API2 — Broken Authentication | Session replay after proxied MFA is an authentication failure mode. |
| Recommendation — Require phishing-resistant auth and invalidate replayable sessions. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authenticators and session assurance directly address this login-bypass pattern. |
| Recommendation — Adopt phishing-resistant authenticators and stronger session assurance. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Token and session handling determines whether stolen auth material can be reused. |
| IA-9 — Service Identification and Authentication | Session replay mitigation depends on strong authentication between client and service. | |
| Recommendation — Shorten authenticator and session lifetime, and revoke compromised tokens quickly. Bind authentication to the intended service and reject replayable sessions. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Replayable sessions undermine access enforcement and privilege boundaries. |
| Recommendation — Restrict and monitor access paths that accept stolen sessions. | ||
Practitioner Guidance
What to verify: Check whether your MFA method is phishing-resistant and whether the resulting session is bound tightly enough to the device or context to make replay difficult. If the answer is no, assume a proxy can turn successful login into successful takeover.
Decision rule: If an application accepts a reusable bearer session with no strong binding, treat that application as vulnerable to AiTM-style replay even when MFA is enforced. Prioritise controls that reduce session reuse value, not just login friction.
What good looks like: The environment should make stolen sessions short-lived, context-sensitive, and anomalous when replayed. A user completing MFA should not be the end of the trust decision when the session itself can later be copied and reused.
Practitioner takeaway: Do not measure MFA effectiveness by successful prompts completed, measure it by whether the resulting session can survive theft and replay.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org