Cybersecurity (cyber security) is a buzzword that seems to have appeared relatively quickly in the world of business IT.  If you search the term “cybersecurity” or “cyber security” on the BBC News website, there are currently 29 pages of articles from the last 2 years, but these are just the major ones that were deemed newsworthy.  

As cybersecurity technicians we reference the Common Vulnerabilities and Exposures (CVE) website which currently lists 166,798 vulnerabilities and this increases daily.  I know, that is a scary number of threats and it changes daily.

In this blog we are going to look at one of the most basic forms of attack which is called a man in the middle cyber attack. Despite being one of the oldest cybersecurity threats it is still widely used today and businesses of all sizes loose thousands of pounds as a result.

Our aim is to raise awareness of the dangers of common cybersecurity attacks that can immobilise businesses, we take a look at man in the middle attacks, how they work and how you can protect against them.

Watch The Man In the Middle Video

Watch the video below to find out more about how man in the middle attacks work.

 

Read Video Transcript

Behind the Hack – Man in the Middle

Every business wants to keep their valuable data safe, but sometimes, without help, it can be hard to identify or stop a breach that would be catastrophic for your business.

Right now our very own ethical hacker is going to show you an example hack that is used every day to get full access to business critical sensitive data and worst of all, he’ll even pretend to be you.

This is called a ‘Man in the Middle’ attack. In this exclusive example it’s instigated by a typical quarantined review email.

Our hacker has worked carefully to make sure it gets through to your main inbox, and looks completely legitimate, but wait, look, the URL has a slight spelling mistake most would miss. 

If you were to see that a message from a colleague has been caught in spam, you’d be compelled to click ‘review’ to find out more, this is called ‘Man in the Middle’ because, in this case there’s a log in portal that appears to be genuine but is actually fake and it’s sat right in between you and the real system you’re trying to access.

Again, there’s that tiny spelling mistake, so you enter your credentials, they get passed through and allow you normal access but at the same time, if we check our hackers machine, they’ve also collected your username and password.  Meaning whatever you can access, they can access.
Just imagine what they can now do… steal your client information, wipe your data and even email using your identity. 

Hackers are well known for resending invoices and asking payment details to be amended, stealing thousands.  All of this without you suspecting a single thing.  Potentially for days, weeks, even months until you finally change your password.

What Is a Man In the Middle Hack?

Also known as eavesdropping attacks, a man in the middle attack occurs when an attacker intercepts communications between two parties. The attacker then eavesdrops and, in most cases, impersonates one of the parties.

The ‘man in the middle’ is the hacker and they must remain undetected in order for the hack to work, often patiently gathering critical information before launching their attack.

How Does a Man In The Middle Attack Work?

When their target has been identified, hackers use methods such as phishing, IP spoofing, stealing browser cookies, creating fake login portals and sending legitimate looking scam emails to deceive the user into entering their login details.

When the hacker has access, they will usually monitor your systems and wait for the right time to strike.

For example, they may use your email address to email clients and ask them to update their payment information so they are instead paying their invoices to the hacker rather than your business.

How To Prevent Man In The Middle Attacks

With proper cyber security measures in place, your business is far less likely to be the victim of an attack. Here’s how you can protect yourself:

  • Train your staff to recognise fraudulent emails and scams.
  • Use email protection to reduce the chances of fraudulent emails getting into your inbox.
  • Use Multi Factor Authentication so that even with your password, the hacker cannot access your systems.
  • Ensure you change your passwords on a regular basis and don’t use the same password for more than one system.
  • Consider using a password management tool to improve the security of your passwords.
  • Use antivirus software to protect your machines and ensure all your software and hardware is kept up to date.
  • Use a professional cyber security provider.
  • Consider Cyber Essentials certification to protect against the most common forms of cyber attack.

Protect Your Business with Absolutely PC

Would your staff be able to spot a man in the middle attack and know what steps to take to prevent a breach occurring as a result?

With just one lapse of concentration, your entire business could be crippled by a cyber attack that costs thousands.

If you want to ensure your business is protected against man in the middle attacks and other forms of cyber attack, call us today on 0117 975 9523 or fill out a contact form and we will get back to you.

 

When Cybercriminals Turn On Each Other, Your Firm Still Loses

When cybercriminals start threatening each other, it can look like good news, even an opportunity. But for a regulated firm, trusting one attacker to rescue you from another is a governance risk, not a lifeline. Here is why the only reliable route through a cyber incident runs through proper protection and trusted support, and how to make sure your firm is ready before the pressure hits.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to “prove you’re human” by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here’s how the trap works, and how to protect your team.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Fake Microsoft Azure Alerts, Why Regulated Firms Must Not Let Their Guard Down

A sophisticated new phishing campaign is exploiting Microsoft Azure Monitor to deliver scam alerts that look entirely legitimate. For regulated firms, where client trust and data governance are non-negotiable, this evolving threat demands a more rigorous approach to email verification and incident response.

Is Your Data Security Keeping Pace With Your Business?

Most professional service firms believe their data security is under control — but confidence and compliance readiness are not the same thing. As cloud platforms, legacy systems and AI tools increase complexity beneath the surface, the gap between perceived security and actual governance grows. This post examines the questions every regulated firm should be asking about where data lives, who has access, and whether the answers would satisfy an auditor.

Why AI is the wrong tool for Passwords

Are the passwords protecting your business as strong as you think they are? AI may seem like a smart shortcut, but when it comes to security, it could be creating hidden weaknesses you can’t afford to ignore.

Beware the Next Generation of Phishing Attacks

Phishing scams are no longer crude or easy to spot. New, smarter attacks are changing the rules — and businesses need to rethink how they stay protected.

Your Browser Knows More Than You Think

Your browser doesn’t just see the websites you visit. It sees patterns, habits, and clues about your business. Most people never check what’s being shared behind the scenes. That’s a risk worth paying attention to.

Old Passwords Are Still Unlocking Systems

Old passwords your team hasn’t used in years could still unlock your systems — and attackers know it. A recent cyber incident revealed how forgotten credentials put professional service firms at serious risk, and why enforcing MFA has never been more important.

Protecting Your Business from Today’s Smarter Digital Fraud

Digital fraud is evolving at a rapid pace, and modern scams are becoming harder to spot than ever. In this article, we explore practical, everyday habits your team can adopt to stay safer online — and how a few simple tools can make a big difference.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.

Business IT Security – Using 2FA

Business IT security is often about doing the basics really well, like securing your accounts using 2FA. In this post find out why 2FA helps to keep your business cyber secure

Cyber Security Infographic

Cyber attacks are no longer something that only happens to large corporations. Small and medium-sized businesses in Bristol and across the UK are increasingly being targeted, and the consequences - data loss, financial damage, reputational harm, and regulatory...

Ransomware – Behind the Hack [Video Guide]

How would your business react if you were locked out of every single file stored on any PC or cloud platform in your network, with the only way to free your data being to pay vast sums of money to a hacker? Well, ransomware does just that. Despite how crippling this...

LastPass Security Breach

LastPass is a password management utility and application allowing companies and people to store their passwords. After a recent breach there are some serious security issues that need attention. This article looks at what these issues are and how to re-secure your passwords.

Phishing Email: Is that email from Microsoft or a phishing attempt?

Update on how realistic phishing attacks are becoming. Could you tell the difference between a real email and a phishing one?

Another Cyber Security zero-day exploit

On 9th November Microsoft released a fix for Windows based computers that allowed an attacker to take control of your systems as an admin.  This was known as CVE-2021-41379 and was the latest in a series of cyber security issues involving Elevation of Privilege...

New Password Management Tool Available from Absolutely PC

With cyber attacks on the rise and remote working becoming commonplace, now, more than ever - businesses need to keep on top of the security of their passwords or be at risk of suffering a costly data breach. A study by Verizon Data Breach Investigations found that...

WordPress Security – Attacks leave 1.6 million sites damaged

Are you confident that your WordPress website is secure? Yesterday, on the 9th of December 2021, 1.6 Million WordPress Sites were Hit With 13.7 Million Attacks In 36 Hours From 16,000 IPs. It’s safe to say this is a major concern to businesses everywhere. WordPress...

Using AI Browsers at Work? You Need to Know This.

AI‑powered browsers can boost productivity, but they also introduce new security and data risks. Learn what businesses need to consider before adopting them.