What it is
A man-in-the-middle (MITM) attack happens when an attacker inserts themselves into the communication between you and a service, to read or alter what passes through. It can happen on a fake or compromised Wi-Fi network, or by manipulating how your device finds websites.
How it works
- 1The attacker gets on the path of the data: with a fake Wi-Fi, on a shared network, or by altering the replies that give a site’s address.
- 2Traffic passes through their device, which can read, copy or modify it.
- 3They can show pages identical to the real ones to capture credentials or payment details.
- 4If they manage to get a fake certificate installed, they may observe part of the protected traffic too.
How to spot it
- Invalid certificate warnings or “not secure” connection on sites you know
- Pages that change look or redirect strangely
- A public network that behaves oddly or asks you to install things
- Requests to install unknown profiles or certificates
How to defend
- Never ignore the browser’s security warnings and use HTTPS sites only
- On untrusted networks use a reliable VPN or your phone’s hotspot
- Do not install certificates or profiles of unknown origin
- Use passkeys or security keys, more resistant to credential capture
- In companies: keep routers and network devices updated and separate guest networks
If you think you have been hit
- Disconnect from the network and switch to a trusted one
- Change the passwords used during the connection and enable multi-factor authentication
- Check for and remove unknown certificates or profiles installed on the device
And there are many, many more
The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.
Contact meOther attacks
Watch the Shorts on YouTubeMatteo Russo · Updated October 2026