Man-in-the-middle attack
Also known as MITM, Adversary-in-the-middle
Intercepting communication between two parties so the attacker can read or alter it while both sides believe the connection is direct.
The version that matters most today is the phishing proxy. The victim is directed to a site that relays every request to the real login page in real time, so the password and the MFA prompt both work normally, while the attacker captures the resulting session token.
This is what defeats app-based MFA codes and push approvals, and it is the specific reason phishing-resistant methods bound to the real domain are worth the migration effort.
Where this comes up
Man-in-the-middle attack sits inside our cybersecurity and threats work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.