Adversary-in-the-Middle (AitM) Attacks and Mitigation Strategies in Healthcare
July 23, 2025 · 4 min read
It is a sophisticated cyber threat that intercepts and manipulates communication between two parties to bypass security measures like multi-factor authentication (MFA). In this post, we discuss how these attacks are delivered in the Healthcare industry and what mitigation strategies are available against such risks.
AitM attacks are delivered to bypass MFA and access Electronic Health Records (EHRs) in the healthcare industry. The process involves several technical and social engineering tactics. Below, I explain how these attacks work, why they are effective against MFA, and their impact on accessing EHRs.
How AitM Attacks Work to Bypass MFA in Healthcare:
1. Initial Access via Phishing:
- Mechanism: Attackers initiate AitM attacks through phishing emails, which account for 23% of cyber incidents in healthcare. These emails trick users (e.g., healthcare staff) into clicking malicious links that lead to fake login pages mimicking legitimate EHR platforms or email services (e.g., Microsoft 365, Epic Systems).
- Tactic: The phishing page is hosted on a domain controlled by the attacker, often using typosquatted URLs or SSL certificates to appear legitimate. For example, a fake login page might be hosted at “micr0soft-login.com” instead of “microsoft.com”.
2. Session Interception:
- Mechanism: When a user enters their credentials on the fake login page, the AitM server captures the username and password in real-time. Simultaneously, the server proxies the login request to the legitimate service (e.g., Microsoft 365 or an EHR system).
- MFA Bypass: As the user enters their MFA code (e.g., a text message code or authenticator app token), the AitM server intercepts this code and relays it to the legitimate service, completing the authentication process. This allows the attacker to gain a valid session token or cookie, granting access to the user’s account without needing to re-authenticate.
3. Session Hijacking and Persistence:
- Mechanism: With the stolen session token, the attacker accesses the victim’s account, including email or EHR systems. The token remains valid until it expires or the user logs out, bypassing the need for further MFA challenges.
- Tactic: Attackers may also deploy malware (e.g., keyloggers) or establish persistent access through compromised accounts, enabling ongoing data exfiltration or manipulation.
4. Exploiting EHR Access:
- Mechanism: In healthcare, compromised credentials grant access to EHR systems containing Protected Health Information (PHI). Attackers can exfiltrate patient data (valued at up to $20,000 per record on the dark web), deploy ransomware (34% of healthcare attacks), or manipulate records for fraud.
- Impact: A single breach can cost $9.77 million and disrupt patient care, with 12% increased mortality risk from downtime and 71% of clinicians noting poor outcomes.
Why AitM Attacks Bypass MFA in 75% of Business Email Compromise (BEC) Cases
- Real-Time Interception: Unlike traditional phishing, AitM attacks capture MFA tokens in real-time, rendering time-based one-time passwords (TOTPs) or SMS codes ineffective. The attacker acts as a proxy, relaying valid credentials and MFA responses to the legitimate service.
- MFA Limitations: Common MFA methods (e.g., SMS, email, or authenticator apps) are vulnerable because they rely on user interaction that can be intercepted. Only 25% of BEC cases use advanced MFA (e.g., hardware tokens or biometrics), which are harder to bypass.
- Social Engineering: Attackers exploit human error, with 46% of healthcare threats linked to inadvertent insiders. Sophisticated phishing pages mimic trusted platforms, tricking even trained staff.
- Session Token Theft: Once the attacker obtains a session token, MFA is irrelevant, as the token grants direct access to systems like Microsoft 365 or EHR platforms without further verification.
The Impact on EHRs
- Data Breaches: Stolen credentials provide direct access to PHI, enabling attackers to sell data or extort organizations (71% of healthcare extortion cases involve ransomware).
- Operational Disruption: Ransomware deployed via AitM attacks can lock EHR systems, causing downtime that delays patient care (12% mortality increase).
- Regulatory Penalties: Breaches violate HIPAA and California’s CCPA, leading to fines and reputational damage (79% of clinicians note financial/legal risks).
How an Identity Security Platform Mitigates AitM Attacks
1. Automated Remediation:
- Detects and blocks compromised accounts in real-time by analyzing login anomalies (e.g., unusual IP addresses or device fingerprints), invalidating stolen session tokens.
- Enforces advanced MFA (e.g., FIDO2 or biometrics) to reduce reliance on vulnerable SMS/TOTP methods.
2. Disaster Recovery:
- Restores AD/Entra ID configurations post-attack, ensuring rapid recovery of EHR access without paying ransoms (23% of healthcare organizations pay to restore systems).
3. Attack Path Analysis:
- Identifies overprivileged accounts and misconfigurations in AD/Entra ID that attackers exploit post-AitM to escalate access to EHR systems.
4. Continuous Threat Detection (MITRE ATT&CK):
- Maps behaviours to MITRE ATT&CK tactics (e.g., T1555 for credential theft, T1078 for valid account abuse), detecting AitM activities like anomalous logins or session token misuse in real-time.