• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Man In The Middle

Also known as: MITM Attack, MitM, On-path Attack, Interception Attack, Bucket Brigade Attack, Janus Attack

COMPROMISE

Attacker secretly intercepts and potentially alters communications between two parties who believe they're communicating directly, commonly exploiting public WiFi networks at coffee shops, hotels, and airports.

Common attack flows

How it fits in a scam

This technique shows up duringCOMPROMISE

Before

This is often where the scam begins.

After

  • Credential TheftCOMPROMISE
  • Cookie HijackingCOMPROMISE

Defense

How to defend against this

How to spot it

  • Unexpected SSL/TLS certificate warnings in browser
  • Browser showing HTTP instead of HTTPS on sites that should be secure
  • Unusually slow network performance on public WiFi
  • Duplicate network names visible in WiFi list
  • Unexpected disconnections followed by reconnection prompts
  • Site security indicators missing such as padlock icon
  • Captive portal pages appearing on previously-connected networks

Tools you can use

  • VPN SoftwareCost low · Effect high
  • Hardware Security KeysCost medium · Effect high

Steps you can take

  • Verify HTTPS ConnectionsCost low · Effect medium

Further reading

  • FTC Consumer Advice

    Public WiFi safety guidance for consumers

  • NSA/CISA

    Securing wireless devices in public settings

  • Imperva

    Technical overview of MITM attack types

  • Wikipedia

    MITM attack types and history

Related techniques

Same stage

  • Credential Theft
  • SIM Swap
  • MFA Fatigue Attack
  • Clipboard Hijacking
  • Malicious App Installation
  • +9 more

Similar defense

  • Data Breach Harvesting
  • Smishing
  • Quishing
  • Account Takeover
  • Lookalike Domain
  • +5 more