Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Session-cookie theft

A browser session is stolen after authentication.

Reference note · Sources below

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Overview
  2. Why it matters
  3. What to check
  4. Sources

Overview

A browser session is stolen after authentication.

Why it matters

The cookie can provide access without another password or MFA challenge.

What to check

Revoke active sessions, inspect extensions and preserve access logs.

Sources

Related reading

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet