---
title: What is a Man-In-The-Middle Attack
description: The growing amount of public networks and users who get connected to them had increased Man-In-The-Middle attack opportunities.
image: https://blog.pradeo.com/hubfs/mitm.png
---

[![pradeo\_logo\_color](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_color.png?width=220&height=33&name=pradeo_logo_color.png "pradeo_logo_color")](https://pradeo.com)

- Solutions 
    - [Mobile Threat Defense](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Secure Private Store](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
    - [Mobile Application Compliance Audit](https://pradeo.com/en/solutions/mobile-application-security/application-compliance-audit/)
    - [Runtime Application Self Protection](https://pradeo.com/en/solutions/mobile-application-security/rasp/)
    - [Shielding](https://pradeo.com/en/solutions/mobile-application-security/application-shielding/)
    - [Application Security Testing](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
- Use cases 
    - [Cybersecurity in MDM/ UEM](https://pradeo.com/en/use-cases/cybersecurity-in-mdm-uem/)
    - [Securing mobile devices](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Securing Mobile Applications](https://pradeo.com/en/solutions/mobile-application-security/application-security-testing/)
    - [Malware / leakware protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Phishing protection](https://pradeo.com/en/solutions/mobile-device-security/mobile-threat-defense/)
    - [Ensuring compliance for applications](https://pradeo.com/en/compliance/)
    - [Ensuring compliance for mobile fleet](https://pradeo.com/en/compliance/)
    - [Securing BYOD](https://pradeo.com/en/solutions/mobile-device-security/secure-private-store/)
- [Become partner](https://pradeo.com/become-partner/)
- Resources 
    - [Solution briefs](https://pradeo.com/en/resources/?solution-briefs)
    - [Customer Cases](https://pradeo.com/en/resources/?customer-cases)
    - [Integration briefs](https://pradeo.com/en/resources/?integration-briefs)
    - [White Papers](https://pradeo.com/en/resources/?white-papers)
    - [Analyst reports & guides](https://pradeo.com/en/resources/?analyst-reports-guides)
    - [On demand webcast](https://pradeo.com/en/resources/?webcasts-on-demand)
    - [About us](https://pradeo.com/en/about/)
- [Blog](https://blog.pradeo.com/)
- [Contact](https://pradeo.com/contact/)
- en 
    - [**FR**](https://blog.pradeo.com/fr)
    - [**DE**](https://blog.pradeo.com/de)

### Topics

- Select a Topic

### Stay up to date

 SUBSCRIBE TO OUR BLOG

### Stay up to date

[Cybersecurity](https://blog.pradeo.com/topic/cybersecurity)

# What is a Man-In-The-Middle Attack

![Picture of Roxane Suau](https://blog.pradeo.com/hubfs/roxane-suau.jpg)

 By [Roxane Suau](https://blog.pradeo.com/author/roxane-suau) on December, 18 2018

[mailto:?subject=Take%20a%20look%20at%20this%20article](mailto:?subject=Take%20a%20look%20at%20this%20article)

![Man In The Middle Attack](https://blog.pradeo.com/hubfs/mitm.png)

Smartphones and tablets have become the first point of access to the internet. This evolution has led to the creation of many Wi-Fi networks so people can connect from almost anywhere, but it opens a new playground for hackers. The growing amount of public networks and users who get connected to them has increased **Man-In-The-Middle** attack opportunities.

A Man-In-The-Middle attack, also known under the acronym MITM, happens when a communication between two parties is **intercepted by an outside entity**. The perpetrator either eavesdrops on the communication or impersonates one of the two parties, making it appear as a regular exchange of data.

 

A Man in The Middle cyberattack targets users of business email accounts, financial applications, e-commerce websites in order to steal their account details, credentials, [bank](https://blog.pradeo.com/white-paper-mobile-banking-regulations-threats-fraud-prevention) account or credit card numbers. The final purpose is to perform **identity theft, illicit money transfers** or **password modifications**.

 

## HOW A MAN IN THE MIDDLE ATTACK WORKS

Most of the time, the **communication between two parties** is intercepted through a Wi-Fi hotspot connection. Hackers create free-access hotspots using legitimate names and make them available to the public. Once a user connects its device to the malicious hotspot, any online data exchange is intercepted by the hacker.

In some other cases, hackers use IP, ARP or DNS spoofing techniques to display their website instead of the original one expected by the user. To do so, they hide their identity behind a trusted IP address (IP Spoofing) or they answer ARP or DNS requests with their own malicious IP address (ARP/DNS spoofing). This type of MITM attack mostly target financial websites.

 

## WHAT A MAN IN THE MIDDLE ATTACK LEADS TO

Once a hacker is in position to intercept data, he can choose either to spy on communications or to tamper with them, for different purposes:

- **Data and identity theft**: A Man-In-The-Middle attack gives the hacker an access to accounts’ login credentials. Once holding these details, he can access sensitive business data (contacts, clients list, contracts…), accounts’ details and steal them.
- **Illicit fund transfer**: Hackers often intercept business email account credentials in order to access employees’ emails and spy on their content to spot an opportunity. For example, if a client is asking to an employee to send him the company’s banking details to make a payment, the hacker can usurp that employee’s email account and send then his own banking details instead of the company’s ones. So the client will transfer money to the attacker’s banking account. The hacker can also retrieve the banking application credentials, connect to the users’ accounts and transfer funds.

 

## HOW TO PROTECT EMPLOYEES FROM MITM ATTACKS

First, employees should be aware of two basic security guidelines:

- Do not connect to public Wi-Fi hotspots (the ones not requiring any login are the riskiest), especially if you are planning on accessing sensitive data, making a fund transfer or accessing a business email account.
- Automatically check certificate authenticity provided by your browser and close any website that is flagged as unsafe or fraudulent.

Secondly, companies should define a security policy in alignment with their data criticality level and use a [Mobile Threat Defense](https://blog.pradeo.com/mobile-threat-defense-the-most-reliable-technology) solution to enforce it. Using a [MTD](https://www.pradeo.com/en-US/mobile-threat-protection) solution allows addressing network, OS and App security threats, while monitoring employees’ devices compliancy with the company’ security policy.

 

---

 

- Discover [PRADEO SECURITY Mobile Threat Defense solution](https://www.pradeo.com/en-US/mobile-threat-protection)
- Download our [Mobile Security Report 2018](https://blog.pradeo.com/mobile-security-threat-report)

###### About The Author

[More from this author](https://blog.pradeo.com/author/roxane-suau)

![](https://blog.pradeo.com/hs-fs/hubfs/roxane-suau.jpg?height=100&name=roxane-suau.jpg)

###### Roxane Suau

#### Recommended articles

[![The FBI warns of an espionage campaign targeting mobile devices](https://blog.pradeo.com/hubfs/Template%20article%20(17)-1.png)](https://blog.pradeo.com/the-fbi-warns-against-an-espionage-campaign-targeting-mobile-devices)

###### [The FBI warns of an espionage campaign targeting mobile devices](https://blog.pradeo.com/the-fbi-warns-against-an-espionage-campaign-targeting-mobile-devices)

 \- January 22, 2026

[![Quishing: when a QR code becomes a trap](https://blog.pradeo.com/hubfs/image%20(6).png)](https://blog.pradeo.com/quishing-when-qr-code-becomes-trap)

###### [Quishing: when a QR code becomes a trap](https://blog.pradeo.com/quishing-when-qr-code-becomes-trap)

 \- December 18, 2025

[![Herodotus: a banking trojan that exposes the limits of an antivirus](https://blog.pradeo.com/hubfs/Template%20article%20(5)-2.png)](https://blog.pradeo.com/herodotus-a-banking-trojan-that-exposes-the-limits-of-an-antivirus)

###### [Herodotus: a banking trojan that exposes the limits of an antivirus](https://blog.pradeo.com/herodotus-a-banking-trojan-that-exposes-the-limits-of-an-antivirus)

 \- November 6, 2025

### Popular articles

### Stay up to date

### Recent articles

### Articles récents

[Fence integrates Pradeo's technology to secure its clients' mobile fleets](https://blog.pradeo.com/fence-integrates-pradeos-technology-to-secure-its-clients-mobile-fleets-1)

 \- 18 December, 2018

[RedHook: the banking trojan that grants itself system-level access on Android](https://blog.pradeo.com/redhook-the-banking-trojan-that-grants-itself-system-level-access-on-android)

 \- 18 December, 2018

[What Google's latest report reveals about mobile threats](https://blog.pradeo.com/what-googles-latest-report-reveals-about-mobile-threats)

 \- 18 December, 2018

[Android: The 4th zero-day vulnerability patched in six months](https://blog.pradeo.com/android-the-4th-zero-day-vulnerability-patched-in-six-months-1)

 \- 18 December, 2018

[Vibe Coding: when AI-generated code multiplies vulnerabilities](https://blog.pradeo.com/vibe-coding-when-ai-generated-code-multiplies-vulnerabilities)

 \- 18 December, 2018

### Topics

- [Mobile Security (56)](https://blog.pradeo.com/topic/mobile-security)
- [Mobile Application Security (46)](https://blog.pradeo.com/topic/mobile-application-security)
- [Expertise (31)](https://blog.pradeo.com/topic/expertise)
- [Security Alert (30)](https://blog.pradeo.com/topic/security-alert)
- [Cybersecurity (29)](https://blog.pradeo.com/topic/cybersecurity)
- [News (28)](https://blog.pradeo.com/topic/news)
- [Partners (25)](https://blog.pradeo.com/topic/partners)
- [Corporate (12)](https://blog.pradeo.com/topic/corporate)
- [Events (4)](https://blog.pradeo.com/topic/events)
- [Actualité (2)](https://blog.pradeo.com/topic/actualité)
- [predictions (2)](https://blog.pradeo.com/topic/predictions)
- [cyberattack (1)](https://blog.pradeo.com/topic/cyberattack)

see all

[![New Call-to-action](https://hubspot-no-cache-eu1-prod.s3.amazonaws.com/cta/default/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f.png)](https://hubspot-cta-redirect-eu1-prod.s3.amazonaws.com/cta/redirect/2378615/ad3111b0-9454-41ff-91f4-9eee95b1f08f)

### Get in touch with mobile security experts

[Contact us](https://www.pradeo.com/en-US/contact-us)

[![](https://blog.pradeo.com/hs-fs/hubfs/pradeo_logo_white_square.png?width=90&height=74&name=pradeo_logo_white_square.png)](https://pradeo.com)

European leader in mobile security, Pradeo protects business mobile devices and applications.

[Read More](https://www.pradeo.com/en-US/)

- [Resources](https://www.pradeo.com/en-US/pradeo-ressources#white_papers)
- [UEM security](https://www.pradeo.com/en-US/uem-mdm-security)
- [Use cases](https://www.pradeo.com/en-US/pradeo-ressources#use-case)
- [Data protection](https://www.pradeo.com/en-US/mobile-data-privacy-regulation)
- [Contact us](https://www.pradeo.com/en-US/contact-us)

- [Mobile Threat Defense](https://www.pradeo.com/en-US/mobile-threat-defense)
- [Mobile Application Security Testing](https://www.pradeo.com/en-US/application-security-testing)
- [In-App Protection](https://www.pradeo.com/en-US/in-app-protection)
- [Secure Private Store](https://www.pradeo.com/en-US/private-app-store)
- [Mobile Threat Intelligence](https://www.pradeo.com/en-US/mobile-threat-intelligence#perso-threat-intelligence)

![email.svg](https://cdn2.hubspot.net/hubfs/3067823/awwal/email.svg "email.svg")

[contact@pradeo.com](mailto:contact@pradeo.com)

Copyright @ 2022. All Right Reserved.

- <https://www.linkedin.com/company/pradeo-security-systems>
- <https://twitter.com/pradeo>
- <https://www.youtube.com/channel/UCD7hgYE8WuipxJtxsHDUdMA>

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Roxane Suau"
  },
  "dateModified" : "January 27, 2021, 1:52:32 PM",
  "datePublished" : "2018-12-18 08:03:18",
  "description" : "The growing amount of public networks and users who get connected to them had increased Man-In-The-Middle attack opportunities.",
  "headline" : "What is a Man-In-The-Middle Attack",
  "image" : {
    "@type" : "ImageObject",
    "url" : "https://cdn2.hubspot.net/hubfs/2378615/mitm.png"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://2378615.fs1.hubspotusercontent-eu1.net/hubfs/2378615/Logo%20Pradeo%20D%C3%A9grad%C3%A9%20Long%20Couleurs.svg"
    },
    "name" : "Pradeo"
  }
}
```