The end of trust at login: Why banking’s new front line is inside the session

Banks have spent years hardening their digital perimeter with multi-factor authentication (MFA), password complexity rules, and device fingerprinting. However, a new wave of cyber threats bypasses the front door entirely.

In partnership with

ebankIT

ebankIT is an international company that develops a leading Omnichannel Digital Banking Platform with capabilities to enable Banks and Credit Unions to run lean, run smart and innovate fast, helping their customers to be one step ahead at a fraction of the cost, time and effort.

08/10/2026 Perspective
Jan Uriga
Qorus Senior Advisor

Banks have spent years hardening their digital perimeter with multi-factor authentication (MFA), password complexity rules, and device fingerprinting. However, a new wave of cyber threats bypasses the front door entirely. Infostealer malware quietly harvests authenticated session tokens and cookies directly from a customer’s compromised device, allowing attackers to hijack active sessions without needing to defeat login controls. In this evolving landscape, the fundamental question for financial institutions is shifting from "How do we verify a user at login?" to "How do we continuously evaluate trust throughout the entire digital session?".

This strategic pivot framed a recent Qorus Community webinar delivered in partnership with ebankIT. Moderated by Jan Uriga (Senior Advisor at Qorus), the panel featured three industry cybersecurity leaders:

  • Stephen Pedersen, Vice President & Information Security Officer at Coast Capital Savings (the largest federal credit union in Canada, serving nearly 750,000 members).
  • Sérgio Magalhães, Executive Board Member and Chief Technology Officer at Millennium bim (Mozambique’s leading bank, affiliated with Millennium BCP).
  • Hilário Coelho, Lead Security Architect at ebankIT (an international omnichannel digital banking platform provider).
“We are not only facing the threat of stealing passwords; we are looking at the threat of stealing an authenticated session.” Hilário Coelho, Lead Security Architect, ebankIT

1. From credentials to intent: The shift to session-level intelligence

Traditional fraud detection models rely heavily on scoring individual transactions at a fixed point in time. However, modern account takeover (ATO) operates as an industrialized attack chain:

  1. Infection: Infostealers compromise the victim's device via phishing, malvertising, or fake CAPTCHAs.

  2. Harvest & sell: Session cookies, passwords, and autofill data are extracted and traded on dark web markets and Telegram.

  3. Validation: AI-powered bots validate stolen credentials and session tokens at scale.

  4. Access: Attackers replay valid session cookies via anti-detect browsers and residential proxies.

  5. Entrenchment: Attackers enroll new devices, alter contact details, and raise transfer limits.

  6. Cash Out: Funds are moved instantly to mule accounts or cryptocurrency wallets.


Because session cookies bypass login MFA, the defensive battleground moves deeper into the user journey. As Hilário Coelho emphasized, attackers are no longer just stealing passwords; they are stealing already-authenticated sessions where MFA has already been passed.

To counter this, banks must shift from static login checks to continuous session-level intent evaluation. As Stephen Pedersen noted, fraud detection must evaluate the sequence of actions across an entire session—detecting anomalies such as a sudden payee addition following a contact detail change—rather than treating each transaction in isolation.

“We need to shift from a login-centric security model to more of a continuous trust evaluation model.” Stephen Pedersen, Vice President & Information Security Officer, Coast Capital Savings

2. Biometrics, liveness, and context: Building a resilient trust layer

To mitigate credential theft and session hijacking, institutions are integrating verified human presence checks. In Mozambique, regulatory frameworks led by the central bank prompted institutions like Millennium bim to implement facial biometrics with liveness detection during remote account opening and high-risk journeys.

As Sérgio Magalhães explained, biometrics should not be limited to initial login. Instead, they function best as a dynamic, risk-triggered step-up control during the session. If a customer attempts a high-value transfer or changes sensitive account settings from an unfamiliar device, a real-time biometric liveness check can confirm legitimate intent even if the session cookie was stolen.

Furthermore, step-up MFA prompts must be heavily contextualized. Simply sending a generic "Approve Login" push notification leaves customers vulnerable to social engineering and adversary-in-the-middle scams. Stephen Pedersenstressed that authorization prompts should explicitly specify the exact payee name, destination, and amount so users can make an informed decision.

“It’s the behavior of the session that will make it trustable or non-trustable.” Sérgio Magalhães, Executive Board Member & Chief Technology Officer, Millennium bim

3. The passkey paradox: Simpler logins, harder recoveries

While there is broad consensus that passkeys and device-bound biometrics will eventually replace passwords over the next 3 to 5 years, passkeys introduce their own operational challenge: account recovery.

Because a passkey is cryptographically bound to a physical device, losing the device creates friction for the legitimate user. Hilário Coelho warned against "fallback vulnerability": if a bank implements passkeys for login but relies on weak fallback channels like SMS OTP or email links for account recovery, the security of the entire account collapses to the weakest link.

To prevent downgrade attacks, banks must re-architect account recovery around strong identity verification—such as re-onboarding via eID, official ID documents with liveness checks, or in-branch verification.

4. Scaling intelligence & shared responsibility

No bank can defend against industrialized e-crime in isolation. Collaboration is expanding beyond basic compromised account lists toward global consortium-based intelligence feeds.

Stephen Pedersen highlighted how Canadian financial institutions share intelligence and leverage global consortium databases for real-time phone and email risk scoring. If an email or phone number is flagged in fraudulent activity at one institution, peer banks can automatically block or flag its use. Additionally, Sérgio Magalhães emphasized the importance of continuous purple-team exercises to test controls against live infostealer tactics and identify detection gaps before attackers exploit them.

Finally, the panel agreed that cybersecurity is a shared responsibility between the bank and the customer. Educating customers on social engineering and introducing interactive in-app tools—such as Millennium BCP's gamified "Security Hub" that evaluates device safety and security awareness—empowers users to act as an active layer of defence.

5. Strategic outlook

The front line of digital banking security has permanently migrated from the login gate to the continuous session. Over the coming years, winning security strategies will rely on:

  1. Device-bound session credentials (e.g., DBSC) to prevent cookie replay.

  2. Continuous session behavioral scoring to detect session drift and bot activity.

  3. Contextualized, dynamic step-up authentication triggered by action intent.

  4. Hardened recovery flows that eliminate weak fallbacks.

Digital Reinvention community

With Qorus memberships, you gain access to exclusive innovation best practices and tailored matchmaking opportunities with executives who share your challenges.

Related Content