You have probably seen the slide
Someone from security puts a fake email on the screen. The sender’s address is slightly wrong. The invoice is urgent. The link points somewhere strange. Everyone agrees that a careful employee should catch it.
You know the rest. Staff complete another awareness course. Security sends a simulation. Management receives a click rate. If the number falls, the firm feels safer.
That story has become one of cybersecurity’s most dangerous half-truths.
Phishing still works. It still deserves filters, training and attention. Yet the suspicious email explains a shrinking share of what a serious intrusion now looks like. Verizon’s 2026 breach analysis put vulnerability exploitation first among initial access vectors, at 31 percent. Phishing accounted for 16 percent. Credential abuse accounted for 13 percent. Mandiant saw the same shift in its own investigations: exploits led for the sixth consecutive year, while highly interactive voice phishing ranked second.
Those figures matter because most boards are still asking a much smaller question: did one of our people click?
Meanwhile, access is being stolen from the browser they use all day, the device they take home, the session they authenticated yesterday and the software sitting at the edge of the network. None of that appears in a phishing simulation score.
Your browser knows more about the firm than most people do
Think about what happens before lunch inside a private bank, family office, trustee or wealth manager.
You open Microsoft 365. Then the client relationship system. Then cloud storage, portfolio reporting, a document room and perhaps an administrative console. You sign in, complete MFA and get on with the day. Each service leaves proof of that successful authentication inside the browser so you do not have to log in again every few minutes.
By then, the browser has become a working copy of your authority.
It holds cookies and session tokens. It remembers devices. It knows which services you use, which accounts belong to you and where you have already proved your identity. Depending on the machine and its configuration, it can also hold saved passwords, autofill data, downloads, extensions and fragments of client work.
Steal the right session and the login has already happened.
The FBI has warned that criminals increasingly target “remember me” cookies because a valid cookie can reopen an email account without asking for the username, password or MFA code again. Mandiant has shown how browser-in-the-middle tooling captures an entire authenticated session and reopens it elsewhere.
From the institution’s side, the entry can look legitimate. The correct identity presents a session the service already trusts. The mailbox is real. The files are real. The writing history is real. Fraud begins inside the account your controls were designed to welcome.
The device underneath the browser decides what MFA is worth
MFA remains essential. Hardware security keys and device certificates make stolen passwords far less useful. Their protection still depends on the condition of the device holding the authenticated session.
Once malware is running on that device, the rules change.
Britain’s National Cyber Security Centre describes what information stealers routinely collect: browser passwords, cookies, form data, card details, screenshots, keystrokes, browser versions and security information. Some packages take enough of the browser profile for a buyer to imitate the original machine.
This is where the conversation becomes uncomfortable for firms that have invested heavily in email security. The infection can begin with a sponsored search result, a poisoned software download, a compromised website, a fraudulent browser update or a fake CAPTCHA prompt. Mandiant observed ransomware access operations using manipulated search results and advertisements to distribute software disguised as legitimate business tools. ENISA documented compromised WordPress sites and fake verification prompts pushing information stealers.
You search for a PDF utility because a client file will not open. You install what appears to be the right tool and return to work. Nothing about the moment feels like a security incident. The danger arrived dressed as useful software through the browser you use every day.
When we see stealer material connected to a financial institution, we do not begin with “who clicked the email?” We ask which device produced it, whether that device belonged to the firm, which browser profile was copied, which sessions existed at the time, which services accepted them and whether the organisation had any visibility on that machine.
Those questions find the exposure. A phishing quiz does not.
Open a criminal marketplace and search your own domain
Cybercrime has turned stolen browser data into inventory.
Searches can be narrowed by company domain, service, country, device or privilege. A listing can include email addresses, saved credentials, cookies, browser fingerprints and a map of the services opened from that machine. Fresh material sells because it has a better chance of working.
Europol and Microsoft identified more than 394,000 Windows computers infected by Lumma Stealer during a two-month period in 2025. Europol described Lumma as a central tool for identity theft and fraud, with stolen credentials, financial information and personal data sold through a dedicated marketplace.
The scale matters. So does the division of labour.
One group spreads the malware. Another sorts the material. Access brokers test the inventory and mark the live accounts. Someone else buys the access and decides whether to steal data, divert money, extort the institution or sell the opportunity again.
Weeks can separate the original infection from the intrusion that finally gets noticed. By then, nobody remembers the download. A password has been changed. The corporate endpoint platform reports nothing because the infected laptop belonged to a contractor, a family member or the employee personally. Meanwhile, the live session still works, or the stolen context points toward another route.
By the time the institution sees an unauthorised payment or an extortion demand, the first five minutes of the crime have vanished from its records.
For private wealth, browser theft gets personal very quickly
Your clients do not share ordinary information with you. They share the architecture of their lives.
A real mailbox can contain family relationships, travel plans, health concerns, liquidity events, legal disputes, signatures, identity documents, tax correspondence and the private reasoning behind major financial decisions. A client relationship system adds contact history. A document room adds structures, holdings and transactions. Internal messages reveal who can approve what and how quickly they usually respond.
Whoever controls the session gets the context.
That context changes the quality of the eventual attack. Payment instructions can arrive from the genuine account. A message can refer to the real meeting, the real lawyer and the real transaction. Timing can match the client’s movements. Tone can match years of correspondence.
Your client will struggle to understand how the message passed every familiar test. It came from the right address. It knew things an outsider should not know. It arrived inside an existing conversation.
The real account carried the fraud.
This is why the fixation on clumsy phishing emails has become so costly. It trains people to look for imitation while modern access lets the criminal operate through the original.
Why the inbox still feels safer
The old model is easy to manage.
You can send 500 test emails, count the clicks and compare the result with last quarter. Everyone understands the chart. Remedial training gives the exercise a neat ending.
Browser, device and session exposure gives you no such comfort. It crosses endpoint security, identity, SaaS administration, browser policy, third-party access, vulnerability management and incident response. It forces awkward conversations about personal devices, contractors, executive exceptions and security tools that only see part of the estate.
It also shifts responsibility away from a single employee and back toward the institution. If a valid session works from another machine, someone designed that session. If a personal laptop can reach client files, someone accepted that access model. If a password reset leaves tokens alive, someone chose the revocation behaviour. If the firm learns about stolen browser material from an external source, its internal monitoring had a boundary.
Your staff can pass the test while your architecture fails it.
What I would ask your security team tomorrow
A serious review begins with evidence. These questions will tell you quickly whether your security programme has moved past the inbox.
Show me every device that can reach sensitive work
Include corporate laptops, executive devices, contractors, outsourced administrators and personal machines. Then show which services each device can reach and which actions require a managed, healthy device. Administrative access from an unmanaged laptop should feel as serious as handing an office master key to someone you have never met.
Show me what survives a password reset
Test the real systems. Revoke a user’s password and inspect every active cookie, refresh token, remembered device, mobile session and third-party application. If the session remains alive, the reset did not contain the account.
Show me how the browser is governed
List permitted extensions. Show how the firm blocks poisoned downloads and unauthorised software. Demonstrate what happens when a process tries to read browser credential stores or copy a profile. Confirm that endpoint coverage follows every device trusted with client information.
Show me what our internal tools cannot see
Internal logs describe the events your systems recorded. They say nothing about an infection on a device outside their reach.
This is why external cyber-threat intelligence matters. Criminal forums, marketplaces, stealer-log sources and access channels can reveal material connected to your people and domains before it is used against you. That evidence still requires careful validation. A stealer record supports collection of the material at some point in time. Device ownership, current access and actual use remain open until endpoint, identity and service records resolve them.
Show me the first hour of the response
When stolen browser material appears, your team should know how to preserve it, identify the likely source device, isolate that device, revoke every session, rotate credentials, remove unauthorised MFA methods and applications, and inspect each affected service for use of the stolen authority.
A password change covers one part of the problem. The session, the device and the evidence still need an answer.
The inbox still deserves protection
Keep the email filters. Keep the simulations. Teach people to stop when a message feels wrong.
Then ask who is watching the browser, who decides which devices deserve trust, who can kill every session and who is looking outside the organisation for access already being sold.
If the answers are vague, you have an email-security programme. Modern cyber defence reaches much further.
The attack has left the inbox. Your security needs to follow it.
