The Five Minutes That Cost a Friend Everything
I'm going to tell you a story about someone I know.
Not a client. Not a statistic. A friend. Let's call him Mark.
Mark is a smart guy. He works in finance. He's careful with his money. He's not the kind of person you'd expect to fall for a phishing scam.
One Tuesday afternoon, he got an email from what looked like his bank. The message said there was unusual activity on his account and he needed to verify his identity. He clicked the link. The page looked exactly like his bank's login page. He entered his username and password.
That took about 15 seconds.
By Friday, the attackers had:
Transferred money out of his checking account
Opened a credit card in his name
Changed the password on his primary email account
Locked him out of his social media accounts
The attack didn't end at the fake login page. That was just the beginning.

What Happens in the First 60 Seconds
The moment someone enters their credentials on a phishing page, the attack chain begins.
The Credential Capture
The credentials are sent to a server controlled by the attacker. Depending on the sophistication of the phishing kit, this can be:
A simple database entry —the username and password are stored in a plain text file or database
A real-time notification —the credentials are sent to a Telegram bot or email address immediately
An AiTM relay —an operator on the other end receives the credentials instantly, logs into the real account, and captures MFA codes in real time
The speed is the thing that surprised Mark the most. He told me:
"I felt a little uneasy after I entered the password. I started thinking I should maybe check. But I didn't. And by the time I did, everything was already gone."
Attackers move fast. That's their advantage.
The Account Check
The attacker immediately tries the captured credentials on the legitimate service. They verify:
Does the username and password work?
What kind of access does the account have?
Are there stored payment methods?
Is there a linked email address?
Is MFA enabled on the account?
If the account works, the attacker has a live, verified credential. The entry point is validated.
The Session Creation
The attacker logs in as the legitimate user. They create a new session. Depending on the security measures of the account, they might be able to:
Change the password immediately
Add a new device to the account
Generate new MFA recovery codes
Add backup email addresses
Once an attacker has a verified session, standard account recovery is usually the hard part for the victim.
The Attack Chain: What Happens Next
Stage 1: Initial Access
This is the phishing page. The user enters their credentials. The attacker now has valid login credentials for the targeted account.
What the attacker can do immediately:
Log in and view account data
Access stored payment methods
View personal information
See linked accounts and services
Stage 2: Privilege Escalation
The attacker tries to increase their level of access to the account.
Common escalation steps:
Adding a new phone number or backup email address
Generating new MFA recovery codes
Changing security questions and answers
Adding a new device to the account
Removing existing trusted devices
From this stage on, the account can be locked by the attacker to regain full access. Account recovery becomes much harder.
Stage 3: Lateral Movement
The attacker uses the compromised account to access other services.
How this works:
Password reuse: If the same password is used elsewhere, the attacker tries it on other services
Password reset: The attacker uses the compromised email account to request password resets for other accounts
Connected apps: The attacker checks the compromised account for connected apps and services
Social links: If it's a social media account, the attacker checks saved contacts and linked accounts
Mark told me he'd used the same password for three different accounts. The attacker tried them all.
Stage 4: Data Extraction
The attacker extracts valuable data from the compromised account.
This can include:
Contacts and addresses
Personal messages and emails
Stored payment methods
Personal documents and photos
Linked accounts and credentials
Behavioral data that could be used for future attacks
The data itself is valuable. It can be sold on dark web markets. It can be used for identity theft. It can be used to target the victim's contacts.
Stage 5: Persistence
The attacker takes steps to ensure they can access the account even if the victim changes the password.
Persistence methods:
Adding a backup email address controlled by the attacker
Adding a new phone number for MFA
Creating new MFA recovery codes
Adding a new device to the account's trusted devices
Enabling app passwords or API keys that bypass normal authentication
By this point, the account is effectively under the attacker's control. The victim may not even realize it's compromised until they try to log in and find they can't.
Stage 6: Monetization
The attacker uses the account to generate financial value.
Common monetization methods:
Financial fraud: Using stored payment methods or applying for credit
Data sale: Selling the extracted data on dark web markets
Ransom: Demanding payment to return access to the account
Identity theft: Using the victim's identity to open new accounts or apply for services
Impersonation: Using the compromised account to scam the victim's contacts
What Makes This Worse: The AiTM Relay
Many modern phishing attacks have moved beyond credential capture.
In an Adversary-in-the-Middle (AiTM) attack, the attacker acts as a real-time relay between the victim and the legitimate service:
The victim enters their credentials on the fake page
The attacker immediately tries those credentials on the real service
If MFA is required, the fake page displays an MFA prompt
The victim enters the MFA code, thinking they're logging in
The attacker intercepts the code and completes the session
The victim's browser is passed through to the legitimate session
What this means:
MFA doesn't stop this type of attack. The code is real. The session is real. The victim is providing what the attacker needs in real time.
The victim may not even realize they've been compromised. They get into the account and everything looks normal. The attacker is in the same account simultaneously.
The attacker can steal the session itself. Once authenticated, the attacker creates new sessions using the existing authentication tokens.
The Mitigations: What Stops These Attacks
Prevention (Before You Enter Credentials)
Tactic | How It Stops the Attack |
|---|---|
Use a password manager | It won't autofill on a fake site; if the URL doesn't match, you have to manually copy the password. That pause helps you check the address. |
Don't click links | Type the URL directly into your browser. If it's a legitimate message, the URL will be the legitimate one. |
Check the URL | Look for subtle differences. A "1" instead of an "l," a different domain (.net instead of .com), or a legitimate-looking domain with extra characters. |
Use MFA | Even if you enter your password, MFA can stop the attack. Just don't enter the MFA code on a page you reached from a suspicious link. |
Detection (After You Enter Credentials)
If you suspect you've entered credentials on a fake page, take action immediately:
Change your password on the legitimate service—right away. If you can log in and change it, do that immediately. If your access has been cut off, contact the provider's support team to initiate account recovery.
Enable or update MFA. If the service allows it, set up MFA or reset your MFA settings. If you have a hardware security key, enroll it to block AiTM attacks.
Generate new recovery codes. If you're able to access the account, invalidate old recovery keys.
Check account activity. Review recent login sessions and logged-in devices. Look for anything you don't recognize.
Remove unknown devices. If you see sessions or devices you don't recognize, sign them out.
Check linked accounts. Look for any connected apps or services you don't recognize.
Monitor for unusual activity. Watch for password resets, new backup email addresses, or changes to contact information.
Change passwords for any other accounts that use the same credential. If you reused the password anywhere else, change it there too.
Recovery (After the Attacker Has Taken Control)
If you've lost access to the account, this becomes a recovery process:
Use the "Forgot Password" feature to reset the password. If the attacker has added a backup email or phone number, you'll need to prove your identity to the provider.
Contact support. Most large services have processes for account recovery. Be prepared to prove your identity and provide evidence that you're the legitimate owner.
Check for changes. Once you regain access, review the account settings carefully. Look for added phone numbers, backup emails, and connected devices.
Report it. If it's a financial account, report the compromise to the service provider and to law enforcement. If it's email or social media, report it to the platform.
What I Told Mark
After Mark told me what happened, I walked him through the steps above.
I told him:
Your bank account is compromised. That's the most urgent. You need to call them immediately and freeze any accounts. You'll need to dispute any unauthorized charges.
Your email account is the control center for your digital life. If the attacker has access to it, they'll try to pivot to other accounts. Use the recovery process to regain access, and if you get in, start with changing the password and removing the attacker's backup methods.
You'll need to change passwords for any account that used the same or similar credentials. Use a password manager and generate strong, unique passwords for each account. Have I Been Pwned can help you see which accounts were exposed, but you should check all of your critical accounts—email, banking, social media, and any financial services—as a baseline.
This is going to take some time. You're going to be frustrated, and you're going to feel like you've lost control. But the process is manageable if you handle it in stages.
I also told him something he needed to hear:
This isn't your fault. You weren't careless. The attack was designed to look legitimate.
The important thing is the response. You've already started it. I'd recommend prioritizing your bank first, then your email, then the other accounts.

The Bottom Line
Entering your password on a fake login page is the start of the attack chain—not the end.
The attack chain continues from credential capture to account takeover to lateral movement to data extraction to monetization. In modern AiTM attacks, MFA can be intercepted in real time, making the attack that much harder to detect.
But the response is the same:
Act quickly
Change credentials on the compromised account
Enable MFA if you haven't
Check for added devices, backup methods, and linked accounts
Monitor for unusual activity
Report the compromise to the service provider
Tell your contacts if the account could be used to impersonate you
The attacks are getting more sophisticated. But the defenses are within reach.
Dave C. — Five minutes now beats five hours later.
No notes on this sheet yet.