Baseline Controls News Resources Glossary About

Adversary-in-the-Middle (AiTM) Phishing

What is Adversary-in-the-Middle (AiTM) Phishing?

A phishing attack that places an attacker-controlled reverse proxy between you and the real login page. You enter your password and approve your multi-factor authentication prompt as normal, the proxy relays both to the genuine identity provider in real time, and the attacker captures the session token that comes back. Nothing is broken and no prompt fails — which is why AiTM defeats SMS codes, authenticator app codes, and push approvals.

How AiTM phishing defeats first-generation MFA →

Why this matters for Canadian businesses

Understanding Adversary-in-the-Middle (AiTM) Phishing is part of building a security programme that meets the 13 Baseline Cyber Security Controls published by the Canadian Centre for Cyber Security (ITSM.10.089) — the Government of Canada's recommended minimum standard for small and medium organizations. You can measure your organization against all 13 controls with our free cybersecurity assessment.

For the wider picture on how Canadian small and medium businesses are performing, see The Cybersecurity Canada Report 2026, our annual benchmark of incident rates, breach costs, and regulation affecting Canadian organizations.

Cite This Page

Suggested citation:

Cybersecurity Canada (2026). Adversary-in-the-Middle (AiTM) Phishing. Retrieved from https://cybersecuritycanada.ca/glossary/aitm-phishing/

Disclaimer: The information provided on this website is for general educational and informational purposes only and does not constitute professional cybersecurity, legal, IT, compliance, or risk management advice. All content, including assessment results, scores, grades, and recommendations, is provided on a best-effort, "as is" basis without warranties of any kind. We expressly disclaim liability for any errors, omissions, or inaccuracies. Organizations should consult with qualified cybersecurity professionals and legal counsel to assess their specific situation. Use of this website or the assessment tool does not create a professional-client relationship. See our Terms of Use for full details.

Cybersecurity Canada is an independent resource and is not affiliated with, endorsed by, or connected to the Canadian Centre for Cyber Security, the Communications Security Establishment, or the Government of Canada.

How does your organization measure up?

Take our free cybersecurity assessment based on the Canadian Centre for Cyber Security's Baseline Controls. 50 questions, under 30 minutes, 100% confidential — your answers never leave your browser.

Take the Free Assessment