Security Explained8 min read1 October 2026

What Is a Man-in-the-Middle Attack? How Hackers Intercept Your Data

A man-in-the-middle attack is when a hacker secretly intercepts communications between two parties. Learn how MITM attacks work, what they target, and how to defend against them.

By Yrzo AI — UK cybersecurity specialists

What Is a Man-in-the-Middle Attack?

A man-in-the-middle (MITM) attack occurs when an attacker secretly intercepts and potentially alters communications between two parties — typically a user and a website or application — without either party knowing. The attacker positions themselves between the two communicating endpoints, reading, recording, or modifying the data passing between them.

The name describes the position of the attacker: sitting silently in the middle of a conversation, invisible to both sides. From the user's perspective, everything looks normal. From the attacker's perspective, they have full access to everything being exchanged — login credentials, session tokens, payment details, personal messages, and any other data transmitted.

How Man-in-the-Middle Attacks Work

**Step 1: Interception**

The attacker first needs to position themselves between the victim and the target system. There are several ways to achieve this:

**ARP spoofing (Address Resolution Protocol)** — on a local network, the attacker sends forged ARP messages that associate their MAC address with the IP address of a legitimate device (such as the default gateway). Traffic from the victim's device intended for the router is redirected to the attacker instead.

**DNS spoofing** — the attacker corrupts the victim's DNS cache, so when the victim types "mybank.com", their device resolves it to the attacker's IP address rather than the bank's real server. The victim is connected to a fake version of the site without realising it.

**Rogue Wi-Fi hotspot** — the attacker sets up a fake Wi-Fi access point with a convincing name ("CoffeeShop_Free_WiFi", "Airport_Guest"). When victims connect, all their traffic passes through the attacker's device. This is one of the most common real-world MITM attack vectors.

**SSL stripping** — when a victim connects to what should be an HTTPS site, the attacker intercepts the connection and downgrades it to HTTP. The victim sees an unencrypted connection (or sometimes nothing unusual, depending on browser warnings). The attacker then communicates with the real site over HTTPS on behalf of the victim, acting as a relay while reading everything in plaintext.

**BGP hijacking** — a large-scale attack targeting internet routing infrastructure, where attackers announce fraudulent Border Gateway Protocol routes to redirect large volumes of traffic through their infrastructure. This is typically nation-state territory.

**Step 2: Decryption (if needed)**

If the intercepted traffic is encrypted, the attacker needs to decrypt it. Against properly implemented HTTPS with a valid certificate, this is computationally infeasible without controlling the certificate authority or exploiting a misconfiguration. This is why HTTPS, HSTS, and certificate pinning are critical defences.

Against weaker encryption, expired certificates, or self-signed certificates that users have been trained to click past, decryption becomes practical.

**Step 3: Attack objectives**

With traffic intercepted, the attacker can: - **Eavesdrop** — read credentials, session tokens, personal data, and communications - **Session hijacking** — steal authentication cookies to impersonate the victim without needing their password - **Data injection** — modify the content of pages or API responses in transit (inserting malicious scripts, changing bank account numbers in payment forms) - **Credential harvesting** — capture usernames and passwords as they are submitted - **Replay attacks** — record and retransmit authentication messages to gain unauthorised access later

Real-World MITM Attack Examples

**Public Wi-Fi credential theft** — an attacker at a coffee shop sets up a rogue hotspot. When victims connect and log into email, social media, or work portals over HTTP or with SSL stripping in play, credentials are captured silently.

**SSL stripping on banking sites** — early implementations of online banking without HSTS (HTTP Strict Transport Security) were vulnerable to attackers intercepting the initial HTTP request before the HTTPS redirect, serving a fake HTTP version of the site and capturing credentials.

**ARP spoofing on corporate networks** — an attacker with access to a corporate Wi-Fi network (via a compromised guest credential, a rogue device, or physical access) poisons the ARP tables of nearby devices, intercepting internal traffic, session tokens, and API calls.

**BGP hijacking of cryptocurrency exchanges** — documented incidents where BGP hijacking redirected DNS traffic for major cryptocurrency services, allowing attackers to intercept and steal login sessions and funds at scale.

How to Detect a Man-in-the-Middle Attack

MITM attacks are designed to be invisible, but some indicators include:

- Unexpected SSL certificate warnings in the browser — the certificate is for an unexpected domain or issuer - Browser warning that a site's certificate has changed since the last visit - Unusually slow network connections (traffic is being proxied through an additional hop) - Network analysis tools (like Wireshark) showing unexpected ARP entries or duplicate MAC addresses - Logins failing despite correct credentials (the attacker may be capturing and discarding rather than relaying)

How to Defend Against MITM Attacks

**Always use HTTPS** — every page of your website must serve over HTTPS, not just login pages. A visitor browsing your site over HTTP can have their session hijacked even before they reach the login form.

**Implement HSTS (HTTP Strict Transport Security)** — the Strict-Transport-Security response header tells browsers to only ever connect to your site over HTTPS, refusing HTTP connections entirely. This prevents SSL stripping attacks. Set a long max-age (at least 31536000 seconds, one year) and include subdomains.

**Use certificate pinning** — mobile applications can pin the expected TLS certificate or public key, rejecting any certificate that does not match even if it is technically valid. This defeats attacks that use fraudulent certificates from compromised certificate authorities.

**Implement HPKP or Certificate Transparency monitoring** — monitor Certificate Transparency logs for unexpected certificates issued for your domain. Google's Certificate Transparency project makes this feasible.

**Enable Secure and SameSite flags on session cookies** — the Secure flag prevents cookies being sent over HTTP. SameSite=Strict or Lax prevents cross-origin requests from carrying session cookies, defending against CSRF and some session hijacking variants.

**Avoid public Wi-Fi for sensitive work** — or use a trusted VPN when connecting via public networks. A VPN encrypts traffic from your device to the VPN endpoint, preventing local network interception.

**Use mutual TLS (mTLS) for APIs** — both client and server authenticate each other's certificates, preventing impersonation attacks in either direction.

**Enable multi-factor authentication** — even if an attacker captures a session token or password, MFA provides an additional barrier to account takeover.

MITM Protections Yrzo AI Tests

Yrzo AI's automated security scan checks several key MITM defences on your website:

- **HTTPS enforcement** — whether your site redirects all HTTP to HTTPS - **HSTS header** — whether Strict-Transport-Security is set with appropriate max-age - **SSL certificate validity** — whether your certificate is valid, not expired, and issued by a trusted authority - **Secure cookie flags** — whether session cookies carry the Secure attribute - **Mixed content** — whether any page resources are loaded over HTTP on an otherwise HTTPS page

These checks form part of the 44-point assessment delivered in under 20 minutes, starting at £99. A site with weak HTTPS configuration is a site that can be attacked in transit — the fix is straightforward once you know what is missing.

Run your scan at yrzoai.dev.

Find out if your website has these vulnerabilities

Yrzo AI runs 44 automated security checks and delivers a full report in under 20 minutes. Starting from £399.

Scan your website →