Jessica Entwistle
August 26 2026
Infosecurity Magazine reports that researchers have identified a phishing-as-a-service platform called ZeroTokens that gives attackers live control of victim sessions in real time, targeting 53 financial brands including banks, payment processors and cryptocurrency platforms. Unlike traditional phishing kits that simply harvest credentials, ZeroTokens acts as a transparent proxy between the victim and the legitimate service, allowing the attacker to observe and manipulate the session as it happens. This enables attackers to bypass multi-factor authentication, intercept one-time codes, and complete fraudulent transactions while the victim believes they are interacting with the genuine service. The platform is being offered as a subscription service to other criminals, lowering the technical barrier for conducting sophisticated phishing attacks that were previously only seen in targeted operations.
This represents the industrialisation of advanced phishing techniques that were previously only seen in targeted attacks by well-resourced threat actors. The real-time session hijacking capability means that even organisations with strong MFA controls can be bypassed if users are tricked into interacting with a ZeroTokens phishing page. For financial services, fintech companies, payment processors and any organisation handling financial transactions, this threat is particularly acute because attackers can complete fraudulent transactions during the live session before security teams have any opportunity to intervene. The fact that this capability is now available as a service means the volume and sophistication of phishing attacks targeting financial services is likely to increase significantly. For UK organisations, this also has implications for customer trust, regulatory compliance and fraud liability, particularly where customers may have been tricked into authorising transactions through a hijacked session.
UK businesses in financial services or handling payment transactions should review whether their fraud detection systems can identify suspicious session behaviour in real time, not just at the point of credential entry. This means looking for anomalies such as rapid changes in user behaviour, unusual transaction patterns, mismatched device fingerprints or geographic inconsistencies during an active session. Consider whether your fraud detection systems can flag transactions that occur immediately after authentication, which is a common pattern in session hijacking attacks. It is also worth reviewing whether your user awareness training covers URL verification and helps users understand that MFA alone is not a complete defence against session hijacking attacks. For organisations providing financial services to customers, consider whether you have clear communication channels to alert customers about phishing campaigns targeting your brand, and whether you have processes for quickly taking down phishing sites when they are identified. The broader lesson is that phishing defences need to extend beyond credential protection to include session monitoring, behavioural analysis and rapid response capabilities.
Source: Infosecurity Magazine