December Trend Sharing Session

Online

Credential Theft Evolved: Session Tokens as the New Keys to the Kingdom
Date: Thu 4 December 2025, 11am ET
Location: Online
Delegates: 100+
Free Registration: Regsister Now!

Adversaries don’t need passwords when they have your tokens!

In this webinar, Eric Clay, Chief Marketing Officer and Research Team Co-Lead and Nick Ascoli, Director Product Strategy, at Flare, will uncover the evolving tradecraft behind session hijacking and cookie theft—two increasingly common techniques leveraged by cybercriminals to bypass MFA, impersonate users, and maintain long-term persistence.

They’ll explore how threat actors harvest and weaponize session tokens, how these credentials are trafficked in the cybercrime underground, and how defenders can identify the telltale signs of a takeover. Using real-world intelligence and Flare data, this webinar will walk through:

– Common collection methods (info-stealers, XSS, token sync abuse)
– How session cookies are used in post-compromise scenarios
– Trends in cookie-based access sales on dark web markets
– Detection strategies and incident response best practices

By the end of this webinar, you’ll understand how session tokens function as high-value credentials—and how attackers exploit this blind spot to bypass even your strongest authentication controls.

Moderator

Christoper Staab - AIconnects

Christopher Staab

Co-Founder, Loyalty Security Alliance

Eric Clay

Eric Clay

CMO, Flare

Nick Ascoli

Nick Ascoli

Director of Product Strategy, Flare

By registering, you submit your information to the webinar organizer and sponsor, who will use it to communicate with you regarding this event and their other services.

LSA December Trends Webinar: Credential Theft Evolved: Session Tokens as the New Keys to the Kingdom

4/12/202511:00am EST1 hour
Adversaries don’t need passwords when they have your tokens!

In this webinar, Eric Clay, Chief Marketing Officer and Research Team Co-Lead and Nick Ascoli, Director Product Strategy, at Flare, will uncover the evolving tradecraft behind session hijacking and cookie theft—two increasingly common techniques leveraged by cybercriminals to bypass MFA, impersonate users, and maintain long-term persistence.

Thery will explore how threat actors harvest and weaponize session tokens, how these credentials are trafficked in the cybercrime underground, and how defenders can identify the telltale signs of a takeover. Using real-world intelligence and Flare data, this webinar will walk through:

- Common collection methods (info-stealers, XSS, token sync abuse)
- How session cookies are used in post-compromise scenarios
- Trends in cookie-based access sales on dark web markets
- Detection strategies and incident response best practices

By the end of this webinar, you’ll understand how session tokens function as high-value credentials—and how attackers exploit this blind spot to bypass even your strongest authentication controls.

This session was hosted together with:

Flareio

Founded in 2016 as the LFPA to allow the various stakeholders in Loyalty, Fraud Prevention and Cybersecurity to collaborate on the growing issues around the security of Loyalty Programs.

LSA_logo_clear100x

Loyalty Security Alliance
brought to you by AiConnects.us


© Copyright 2025 All Rights Reserved