RESOURCES · SECURITY & EMAIL

Hacked despite MFA?
Token theft, explained

You did everything right — a strong password and multi-factor authentication switched on — and somehow an attacker still got into your Microsoft 365 or Google account. How? Increasingly, it's a trick called token theft (also known as token replay). Here's what it means, in plain English — and what to do if it happens to you.

Applies to: Microsoft 365 / Google Workspace Read: ~4 min Level: Non-technical
Quick answer

When you log in and pass MFA, your account is handed a temporary "digital wristband" (a session token) so you're not asked to prove who you are again all day. If an attacker steals that wristband, they can walk into your account without your password and without triggering MFA. The fix if it happens: your IT team revokes the sessions (which cancels the stolen wristband), resets the password, and checks for damage. A password reset alone is not enough.

THE SIMPLE VERSION

Think of a music festival.

It's the easiest way to picture what's really going on:

Token theft is simply stealing the wristband. Once someone has it, they don't need your ticket or your ID — they just walk in. That's why an attacker can be inside your mailbox even though your password is secret and your MFA is switched on.

HOW THE WRISTBAND GETS STOLEN

Three common ways it happens.

  1. A fake login page (the most common)An email nudges you to sign in. The link opens a page that looks exactly like the real Microsoft or Google login. You type your password and approve MFA as normal — but the fake page is sitting invisibly in the middle, quietly copying the wristband the real service hands back. To you, everything looked completely normal.
  2. Sneaky software on a device"Information-stealing" malware — often picked up from a dodgy download, attachment or cracked app — copies the saved logins and wristbands stored in your web browser and sends them to the attacker.
  3. A bad browser add-on or an already-hacked computerA malicious browser extension, or a device that's already compromised, can quietly lift session wristbands in the background too.
Why MFA didn't "fail". This is the confusing part: MFA worked perfectly. The attacker didn't crack it — they just reused a session that had already passed it. That's why these break-ins are often called an "MFA bypass" even though nothing about your MFA was actually broken.
WARNING SIGNS

What token theft looks like from the outside.

You won't see anything dramatic — that's the danger. Watch for the quiet signs:

For the technically curious: in Microsoft 365 or Google sign-in logs, IT often sees a successful login where MFA was "satisfied by a claim in the token" — meaning an existing session was reused rather than a fresh MFA challenge — paired with an unfamiliar location or device. To a security team, that combination is a strong signal of a stolen token.

WHAT TO DO NOW

If you suspect token theft, act fast.

  1. Report it immediatelyTell your IT or security team the moment something feels off, and let your manager know. Speed is everything — the sooner they act, the less an attacker can do.
  2. Revoke the sessions (the crucial step)Your IT team signs the account out everywhere, which cancels the stolen wristband. This is the step that actually locks the attacker out — see the warning below.
  3. Reset the passwordChange it from a clean, trusted device — and anywhere the same password was reused.
  4. Re-check MFAConfirm MFA is on, remove any method you don't recognise, and re-register it. This is a good moment to move to stronger, "phishing-resistant" MFA.
  5. Hunt for what they touchedHave IT check for hidden mailbox rules, unexpected app permissions (OAuth consents), and sent emails you didn't send.
  6. Check everyone elseAttackers use one mailbox to phish colleagues, so IT should look for other affected accounts and warn your contacts.
A password reset alone will not fix this. A stolen wristband can keep working even after you change your password. The step that actually stops the attacker is revoking the sessions (signing the account out everywhere). Always do both — revoke sessions and reset the password — then check for changes they may have left behind.
MFA IS A START, NOT THE FINISH LINE

Modern attacks slip past basic MFA. Can yours be caught?

Token theft is exactly the kind of attack that gets past a "we've got MFA" tick-box. Our free IT Health Check reviews your Microsoft 365 or Google security, sign-in protections and monitoring — and shows you how to add the layers that catch stolen-session attacks early, or stop them landing at all.

KEEP READING

Related resources