{"id":51113,"date":"2026-05-29T09:56:04","date_gmt":"2026-05-29T07:56:04","guid":{"rendered":"https:\/\/www.ebas.ch\/?p=51113"},"modified":"2026-05-29T09:56:04","modified_gmt":"2026-05-29T07:56:04","slug":"phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa","status":"publish","type":"post","link":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/","title":{"rendered":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA"},"content":{"rendered":"<div id=\"av_section_1\" class=\"avia-section av-3osj-8edf3c5c57d6f444e32a620ab19c7a5a main_color avia-section-default avia-no-border-styling  avia-builder-el-0  avia-builder-el-no-sibling  avia-bg-style-scroll container_wrap fullsize\"><div class=\"container av-section-cont-open\"><main role=\"main\" itemprop=\"mainContentOfPage\" class=\"template-page content  av-content-full alpha units\"><div class=\"post-entry post-entry-type-page post-entry-51113\"><div class=\"entry-content-wrapper clearfix\">\n<div class=\"flex_column av-px9rrb-6c0519768a3ffea4b355604292b74ae9 av_three_fourth  avia-builder-el-1  el_before_av_one_fourth  avia-builder-el-first  first flex_column_div  \"><section class=\"av_textblock_section av-kj04vgvy-0d24a80e61809aaf6aed5c881b7b943a \" itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\" itemprop=\"blogPost\"><div class=\"avia_textblock\" itemprop=\"text\"><p class=\"ebas-lead\">Cyber-criminals continuously keep developing their phishing methods further. And so-called &ldquo;man in the middle&rdquo; attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.<\/p>\n<p>Compared to classic <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> websites, <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Man-in-the-Middle (MitM)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;With a Man-in-the-Middle attack, a third party or a malware will intervene into an e-banking session by interposing itself unnoticed between a user&rsquo;s device and a financial institution&rsquo;s server, to then take control of data traffic.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MitM<\/span> attacks don&rsquo;t just copy a log-in page. Their fraudulent infrastructure directly passes on every input to the correct service, while showing victims the legitimate website. This is why people often don&rsquo;t notice these attacks. Even <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Multi-factor authentification (MFA)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Multi-factor authentification is a security procedure which involves checking a user&rsquo;s identity via a combination of several independent factors. Such factors could for instance be passwords, scanning QR codes or biometric characteristics. Using MFA reduces the risk of unauthorised access as any attacker would have to overcome several hurdles posed by separate factors to obtain access. The best-known type of multi-factor authentification is two-factor authentification (2FA).&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">multi-factor authentification (MFA)<\/span> can sometimes be bypassed.<\/p>\n<p><strong>Attacks are clearly on the increase<\/strong><\/p>\n<p>In Switzerland, the threat posed by <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> keeps growing. There is currently a particularly treacherous type of <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> doing the rounds &ndash; man in the middle <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span>. Cyber-criminals increasingly employ new hosting technologies and hard-to-recognise infrastructures in the process.<\/p>\n<p><strong>This is how <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Man-in-the-Middle (MitM)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;With a Man-in-the-Middle attack, a third party or a malware will intervene into an e-banking session by interposing itself unnoticed between a user&rsquo;s device and a financial institution&rsquo;s server, to then take control of data traffic.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MitM<\/span> <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> attacks work<\/strong><\/p>\n<p>Attacks often start with a seemingly harmless e-mail, text or WhatsApp message containing a <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Hyperlink&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is a cross reference, for instance to websites, which makes it possible to jump to another electronic document or a different location inside a document when clicked. On the WWW, the target addresses of such jumps could also be other websites.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>link<\/span> to a faked log-in page. If victims click on it to log in, <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;User name&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This is the name used by users to identify themselves in a system. When logging into a program or service (e. g. when e-banking), you will usually be asked for a user name and password. These will serve to identify authorised users.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">user name<\/span>, <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> and sometimes even the <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Multi-factor authentification (MFA)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Multi-factor authentification is a security procedure which involves checking a user&rsquo;s identity via a combination of several independent factors. Such factors could for instance be passwords, scanning QR codes or biometric characteristics. Using MFA reduces the risk of unauthorised access as any attacker would have to overcome several hurdles posed by separate factors to obtain access. The best-known type of multi-factor authentification is two-factor authentification (2FA).&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MFA<\/span> code are passed on to the legitimate website in real time. At the same time, attackers obtain access to this active session.<\/p>\n<p>Particularly perfidious: Many attackers use several instances of redirection and professionally designed websites to bypass security systems. Sometimes even specialised cloud services or decentralised platforms are used so that <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>phishing<\/span> pages can remain online for longer.<\/p>\n<p><strong>How private individuals and companies can protect themselves.<\/strong><\/p>\n<p>There is no total protection. Still, you can considerably reduce the risks:<\/p>\n<ul>\n<li>Critically question log-in links contained in e-mails, text or messenger notifications<\/li>\n<li>Thoroughly check the Internet address<\/li>\n<li>Use a <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> manager<\/li>\n<li>Apply modern <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Multi-factor authentification (MFA)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Multi-factor authentification is a security procedure which involves checking a user&rsquo;s identity via a combination of several independent factors. Such factors could for instance be passwords, scanning QR codes or biometric characteristics. Using MFA reduces the risk of unauthorised access as any attacker would have to overcome several hurdles posed by separate factors to obtain access. The best-known type of multi-factor authentification is two-factor authentification (2FA).&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MFA<\/span> methods such as FIDO2 or <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Passkey&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;A &amp;quot;passkey&rdquo; is a passwordless log-in method, consisting of a public and a private key, with the secret key always remaining on a local device such as a smartphone or USB stick, never leaving them. The device itself acts as a means of authentification. Contrary to passwords, passkeys are therefore device- and not person-specific.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>passkey<\/span> solutions if available<\/li>\n<li>Keep your <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Operating system&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;A program run on a device to manage system resources, such as processor, storage media and input and output devices, and which offers these resources to application programs (software). Some well-known operating systems are Windows, macOS, Linux, Android and iOS.&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">operating system<\/span>, <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Browser&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;A special computer program to display websites on the World Wide Web (WWW) or data and documents in general. The most important browsers used on the Internet are Google Chrome, Mozilla Firefox, Microsoft Edge and Apple Safari.&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>browser<\/span> und security software up to date at all times<\/li>\n<li>Sensitise your employees and train them regularly<\/li>\n<\/ul>\n<p>It is also important to thoroughly check suspicious log-in or unexpected <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Multi-factor authentification (MFA)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Multi-factor authentification is a security procedure which involves checking a user&rsquo;s identity via a combination of several independent factors. Such factors could for instance be passwords, scanning QR codes or biometric characteristics. Using MFA reduces the risk of unauthorised access as any attacker would have to overcome several hurdles posed by separate factors to obtain access. The best-known type of multi-factor authentification is two-factor authentification (2FA).&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MFA<\/span> requests. If you suddenly receive several <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Multi-factor authentification (MFA)&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Multi-factor authentification is a security procedure which involves checking a user&rsquo;s identity via a combination of several independent factors. Such factors could for instance be passwords, scanning QR codes or biometric characteristics. Using MFA reduces the risk of unauthorised access as any attacker would have to overcome several hurdles posed by separate factors to obtain access. The best-known type of multi-factor authentification is two-factor authentification (2FA).&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>MFA<\/span> confirmations without having logged in anywhere, you should change your <span class=\"glossaryLink\" aria-describedby=\"tt\" data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Password&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;Serves for authentication. This means agreeing on and using a character string for someone, usually a person, to identify themselves and confirming their own identity this way.&lt;\/p&gt;\n&lt;p&gt;A &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/4-protecting-online-access\/&amp;quot;&amp;gt;good password&amp;lt;\/a&amp;gt; should have at least 12 characters and consist of numbers, upper and lower case letters as well as special characters.&lt;\/p&gt;&lt;\/div&gt;\n\" data-mobile-support=\"0\" data-gt-translate-attributes=\"[{&quot;attribute&quot;:&quot;data-cmtooltip&quot;, &quot;format&quot;:&quot;html&quot;}]\" tabindex=\"0\" role=\"link\">password<\/span> straight away and terminate all active sessions.<\/p>\n<p><strong>Humans remain the most important protection factor<\/strong><\/p>\n<p>In spite of modern security technologies, humans remain a central target of all cyber-criminals. <span class=\"glossaryLink\"  aria-describedby=\"tt\"  data-cmtooltip=\"&lt;div class=glossaryItemTitle&gt;Phishing&lt;\/div&gt;&lt;div class=glossaryItemBody&gt;This term is made up from the words &amp;quot;password&rdquo; and &amp;quot;fishing&rdquo;. Attackers use &amp;lt;a href=&amp;quot;https:\/\/www.ebas.ch\/en\/phishing\/&amp;quot;&amp;gt;phishing&amp;lt;\/a&amp;gt; to obtain confidential data from unsuspecting Internet users. These might for instance involve access data for your e-banking facility or account information of online shops. Perpetrators abuse their victims&rsquo; good faith and helpfulness by purporting to be, say, an employee of a trustworthy financial institution.&lt;\/p&gt;\n&lt;p&gt;There are a variety of other variations such as Vishing (voice phishing or phone phishing), Smishing (SMS \/ text phishing) and QR phishing in addition to classic phishing via e-mail.&lt;\/p&gt;&lt;\/div&gt;\n\"  data-mobile-support=\"0\"  data-gt-translate-attributes='[{\"attribute\":\"data-cmtooltip\", \"format\":\"html\"}]' tabindex='0' role='link'>Phishing<\/span> attacks are specifically based on time pressure, trust and habits. It is therefore important to remain vigilant and apply a healthy dose of suspicion in digital everyday life.<\/p>\n<\/div><\/section><\/div><div class=\"flex_column av-jk6frd-ce34560b59c9a24e74b1939a23f3d29e av_one_fourth  avia-builder-el-3  el_after_av_three_fourth  avia-builder-el-last  flex_column_div  \"><\/div>\n<\/div><\/div><\/main><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.<\/p>\n","protected":false},"author":7,"featured_media":2919,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[25],"tags":[],"class_list":["post-51113","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"yoast_head":"<title>Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb<\/title>\n<meta name=\"description\" content=\"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb\" \/>\n<meta property=\"og:description\" content=\"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/\" \/>\n<meta property=\"og:site_name\" content=\"\u00abeBanking \u2013 but secure!\u00bb\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-29T07:56:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/11\/facebook_default.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1800\" \/>\n\t<meta property=\"og:image:height\" content=\"1080\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"eBanking \u2013 aber sicher!\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"eBanking \u2013 aber sicher!\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/\"},\"author\":{\"name\":\"eBanking \u2013 aber sicher!\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/person\\\/f61abb02f6103eedce795ac96d013347\"},\"headline\":\"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA\",\"datePublished\":\"2026-05-29T07:56:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/\"},\"wordCount\":1283,\"publisher\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/news.svg\",\"articleSection\":[\"News\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/\",\"name\":\"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/news.svg\",\"datePublished\":\"2026-05-29T07:56:04+00:00\",\"description\":\"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/news.svg\",\"contentUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/news.svg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/2026\\\/05\\\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"News\",\"item\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/category\\\/news\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\",\"name\":\"\u00abeBanking \u2013 but secure!\u00bb\",\"description\":\"\u00abeBanking \u2013 but secure!\u00bb is an independent platform meant to help you maintain your personal computer security.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#organization\",\"name\":\"\u00abeBanking \u2013 aber sicher!\u00bb\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/logo_ebas_de.svg\",\"contentUrl\":\"https:\\\/\\\/www.ebas.ch\\\/wp-content\\\/uploads\\\/2020\\\/06\\\/logo_ebas_de.svg\",\"width\":10,\"height\":1,\"caption\":\"\u00abeBanking \u2013 aber sicher!\u00bb\"},\"image\":{\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.ebas.ch\\\/en\\\/#\\\/schema\\\/person\\\/f61abb02f6103eedce795ac96d013347\",\"name\":\"eBanking \u2013 aber sicher!\"}]}<\/script>","yoast_head_json":{"title":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb","description":"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/","og_locale":"en_US","og_type":"article","og_title":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb","og_description":"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.","og_url":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/","og_site_name":"\u00abeBanking \u2013 but secure!\u00bb","article_published_time":"2026-05-29T07:56:04+00:00","og_image":[{"width":1800,"height":1080,"url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/11\/facebook_default.png","type":"image\/png"}],"author":"eBanking \u2013 aber sicher!","twitter_card":"summary_large_image","twitter_misc":{"Written by":"eBanking \u2013 aber sicher!","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#article","isPartOf":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/"},"author":{"name":"eBanking \u2013 aber sicher!","@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/person\/f61abb02f6103eedce795ac96d013347"},"headline":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA","datePublished":"2026-05-29T07:56:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/"},"wordCount":1283,"publisher":{"@id":"https:\/\/www.ebas.ch\/en\/#organization"},"image":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/09\/news.svg","articleSection":["News"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/","url":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/","name":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA - \u00abeBanking \u2013 but secure!\u00bb","isPartOf":{"@id":"https:\/\/www.ebas.ch\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#primaryimage"},"image":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#primaryimage"},"thumbnailUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/09\/news.svg","datePublished":"2026-05-29T07:56:04+00:00","description":"Cyber-criminals continuously keep developing their phishing methods further. And so-called \u201cman in the middle\u201d attacks (MitM) are particularly dangerous. In the process, attackers interposition themselves in between a legitimate website and their victim without them realising, allowing the fraudsters to capture access data in real time.","breadcrumb":{"@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#primaryimage","url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/09\/news.svg","contentUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2019\/09\/news.svg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.ebas.ch\/en\/2026\/05\/phishing-is-becoming-ever-more-cunning-how-man-in-the-middle-attacks-circumvent-even-mfa\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.ebas.ch\/en\/"},{"@type":"ListItem","position":2,"name":"News","item":"https:\/\/www.ebas.ch\/en\/category\/news\/"},{"@type":"ListItem","position":3,"name":"Phishing is becoming ever more cunning: How \u201cMan in the middle\u201d attacks circumvent even MFA"}]},{"@type":"WebSite","@id":"https:\/\/www.ebas.ch\/en\/#website","url":"https:\/\/www.ebas.ch\/en\/","name":"\u00abeBanking \u2013 but secure!\u00bb","description":"\u00abeBanking \u2013 but secure!\u00bb is an independent platform meant to help you maintain your personal computer security.","publisher":{"@id":"https:\/\/www.ebas.ch\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.ebas.ch\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.ebas.ch\/en\/#organization","name":"\u00abeBanking \u2013 aber sicher!\u00bb","url":"https:\/\/www.ebas.ch\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/06\/logo_ebas_de.svg","contentUrl":"https:\/\/www.ebas.ch\/wp-content\/uploads\/2020\/06\/logo_ebas_de.svg","width":10,"height":1,"caption":"\u00abeBanking \u2013 aber sicher!\u00bb"},"image":{"@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.ebas.ch\/en\/#\/schema\/person\/f61abb02f6103eedce795ac96d013347","name":"eBanking \u2013 aber sicher!"}]}},"_links":{"self":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/posts\/51113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/comments?post=51113"}],"version-history":[{"count":2,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/posts\/51113\/revisions"}],"predecessor-version":[{"id":51148,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/posts\/51113\/revisions\/51148"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/media\/2919"}],"wp:attachment":[{"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/media?parent=51113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/categories?post=51113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.ebas.ch\/en\/wp-json\/wp\/v2\/tags?post=51113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}