Cyber Defence
Cyber Security

What is a Man-in-the-Middle (MITM) Attack? (2026)

A Man-in-the-Middle (MITM) attack is when a hacker secretly intercepts communication between you and a website or app to steal data like passwords, OTPs and UPI details. Learn how MITM attacks work and how to prevent them in 2026.

What is a Man-in-the-Middle (MITM) Attack? (2026)
Amit Kumar
Amit KumarEthical Hacker & Founder
8 min read

Short answer: A Man-in-the-Middle (MITM) attack is when a hacker secretly positions themselves between you and a website, app or network to intercept, read or alter the data flowing between the two. They use it to steal passwords, OTPs, card details and UPI credentials without either side noticing.

Every time you log in to your bank, pay by UPI or send a message, your data travels across networks you do not control. A Man-in-the-Middle attack turns that journey into a trap. Instead of your information going straight to the server, it passes through an attacker who quietly copies or changes it. This guide explains how MITM attacks work, the common types, real-world Indian scenarios, and the practical steps that keep you safe in 2026.

What is a Man-in-the-Middle attack?

A Man-in-the-Middle attack is a form of eavesdropping where the attacker secretly relays and possibly alters the communication between two parties who believe they are talking directly to each other. Imagine posting a letter, but a stranger opens it, reads it, maybe changes a line, reseals it and sends it on. Neither the sender nor the receiver realises anyone interfered.

In the digital world this can happen on a compromised Wi-Fi network, a fake website, a poisoned DNS response or an infected router. Because the attacker sits in the middle of the conversation, they can capture login credentials, session cookies, OTPs, and even inject malicious content into pages you view.

How does a MITM attack work?

A typical MITM attack has two stages: interception and decryption.

  • Interception: The attacker gets between you and your destination, often by creating a rogue Wi-Fi hotspot, spoofing a router (ARP spoofing), or poisoning DNS so your requests go to their server.
  • Decryption or manipulation: If the traffic is unencrypted or the encryption is downgraded, the attacker reads it directly. With techniques like SSL stripping, they trick your browser into using insecure HTTP so they can see everything in plain text.

Once in the middle, the attacker can silently log everything, replay your session to impersonate you, or alter transactions, for example changing the destination account of a payment.

Common types of MITM attacks

TypeHow it worksMain risk
Rogue Wi-Fi hotspotAttacker sets up a free Wi-Fi named like a cafe or airportAll your traffic passes through them
ARP spoofingAttacker tricks devices on a LAN into sending traffic through their machineLocal network eavesdropping
DNS spoofingCorrupts DNS so a legit URL loads a fake siteCredential theft on cloned sites
SSL strippingDowngrades HTTPS to HTTP to read encrypted dataPlain-text password capture
Session hijackingSteals your session cookie to impersonate youAccount takeover without a password
Email hijacking (BEC)Intercepts business email to alter invoice or bank detailsLarge fraudulent transfers

MITM attacks in the Indian context

MITM techniques power several frauds familiar to Indian users:

  • Public Wi-Fi banking: Logging into a banking app or entering a UPI PIN on free railway-station or cafe Wi-Fi can expose credentials if the network is rogue or poisoned.
  • Fake payment pages: DNS spoofing or a phishing link can send you to a clone of your bank or a shopping site, capturing your OTP and card details in real time. This overlaps closely with phishing attacks.
  • Invoice tampering: In business email compromise, attackers intercept email threads and change the bank account on an invoice, diverting payments meant for a genuine vendor.
  • Session hijacking: If a shopping or wallet session cookie is stolen, an attacker can transact as you without ever needing your password.

Warning signs of a MITM attack

  • Your browser shows a certificate warning or the padlock disappears on a site that normally has HTTPS.
  • A familiar website suddenly looks slightly different or asks for extra details.
  • You are unexpectedly logged out or asked to log in again repeatedly.
  • Web pages load over HTTP when they should be HTTPS.
  • Transactions or messages behave oddly, such as a payment going to an unfamiliar account.

How to prevent MITM attacks

For everyday users

  • Always look for HTTPS and a valid padlock before entering any credentials, and never bypass certificate warnings.
  • Avoid banking on public Wi-Fi. Use mobile data or a trusted VPN when you must use an open network.
  • Enable two-factor authentication so a stolen password alone cannot unlock your account.
  • Keep your browser, OS and apps updated to close vulnerabilities that enable SSL stripping and session theft.
  • Type important URLs yourself or use bookmarks instead of clicking links in SMS or email.
  • Verify bank-account changes on invoices by phone before paying, to defeat email tampering.

For businesses and networks

  • Enforce HTTPS everywhere with HSTS so browsers refuse insecure connections.
  • Use strong Wi-Fi encryption (WPA3), network segmentation and monitoring for ARP anomalies.
  • Deploy DNSSEC and reputable DNS resolvers to reduce DNS spoofing.
  • Use VPNs for remote staff and mutual TLS for sensitive internal services.

MITM vs other attacks: how it differs

MITM is often confused with phishing and eavesdropping, but the differences matter for defence. In phishing, you are lured to a fake destination and hand over data voluntarily. In a pure MITM attack, you may be visiting the genuine site, but the attacker silently sits on the path in between, reading or altering traffic without you ever leaving the real service. This is why MITM can be harder to notice; there is no obvious fake link to spot. The common thread is that both rely on breaking trust, whether trust in a link or trust in the network path.

Because MITM operates at the network and protocol level, technical controls like HTTPS, HSTS, certificate pinning and secure DNS carry more weight than awareness alone. A user cannot always see interception happening, so the system must be designed to refuse insecure connections in the first place.

Real-world MITM scenarios to watch

  • The airport lounge: A rogue hotspot named like the official Wi-Fi captures logins from travellers checking bank balances.
  • The shared office router: A compromised or misconfigured router lets an insider run ARP spoofing across the LAN.
  • The vendor invoice: An intercepted email thread has its bank account quietly swapped, sending a large payment to the attacker.
  • The look-alike login page: DNS spoofing routes a correctly typed URL to a cloned page that harvests the OTP in real time.

In each case, the fix is the same set of habits: verify certificates, avoid untrusted networks for sensitive tasks, and confirm any change to payment details out of band.

How to respond if you suspect a MITM attack

If you believe your connection has been intercepted, act quickly to limit the damage:

  • Disconnect from the suspicious network immediately and switch to mobile data or a trusted connection.
  • Do not enter any credentials until you are on a network you trust.
  • Change the passwords of any accounts you accessed on that network, ideally from a different device.
  • Enable or re-verify multi-factor authentication on those accounts.
  • Check for unauthorised transactions and report financial fraud on helpline 1930 or at cybercrime.gov.in.
  • Update your device and browser, and run a security scan in case malware was installed.

For sensitive work, always assume public networks may be hostile. Treating every open Wi-Fi as untrusted, and relying on HTTPS, VPNs and 2FA, closes off the vast majority of MITM opportunities before they can start.

Learn to defend networks with Cyber Defence

Understanding attacks like MITM is exactly what ethical hackers train for. Cyber Defence is an ISO-certified, GeM-registered institute in Hisar led by founder Amit Kumar (CEH, CRTA). Our cyber security course (₹15,000, 3–4 months) builds strong fundamentals in network safety, while the ethical hacking course (₹60,000, 6 months) teaches network penetration testing, secure protocols and defensive design in a hands-on lab. Browse our courses, learn what cyber security is, or call +91-75175-72000.

FAQ

What is a Man-in-the-Middle attack in simple words?

It is when a hacker secretly sits between you and a website or app, reading or changing the information you exchange without either side realising it. They use it to steal passwords, OTPs and payment details.

Can a MITM attack happen on public Wi-Fi?

Yes. Public Wi-Fi is one of the most common places for MITM attacks because attackers can set up rogue hotspots or intercept traffic on open networks. Avoid banking on public Wi-Fi and use mobile data or a VPN.

Does HTTPS protect against MITM attacks?

HTTPS strongly protects your data by encrypting it, but attackers may try SSL stripping to downgrade the connection. Always check for a valid padlock, never ignore certificate warnings, and keep your browser updated.

How can I tell if I am being targeted by a MITM attack?

Warning signs include certificate errors, a missing padlock, sites loading over HTTP, repeated logouts, or a familiar page looking slightly different. Stop and verify before entering any credentials.

Does a VPN prevent Man-in-the-Middle attacks?

A trusted VPN encrypts your traffic end to end, which makes interception on untrusted networks much harder. It is a strong protection on public Wi-Fi, but should be combined with HTTPS and 2FA.

Can I learn to detect and stop MITM attacks?

Yes. Ethical hacking and network security training covers how these attacks work and how to defend against them. Cyber Defence in Hisar offers hands-on courses for exactly this.

Ready to master network security? Call Cyber Defence, Hisar at +91-75175-72000 or explore our ethical hacking course.

Talk to a Cyber Defence Expert

Get a free consultation on cybersecurity, training and certifications. Our team responds within 10 minutes during business hours.