Attack in which a third party secretly interposes between two communicating parties to intercept, read or alter their exchanges without their knowledge.
In a MitM attack, the attacker positions themselves between two entities that believe they are communicating directly, in order to eavesdrop on or modify their exchanges. Classic vectors include ARP spoofing on a local network, DNS poisoning, the creation of rogue Wi-Fi access points and, in certain contexts, the compromise of TLS certificates. End-to-end encryption and certificate pinning are the main technical countermeasures. The most feared contemporary variant in financial markets is the MitM attack between a broker and its clearing house, or between an AI model and its production API, enabling the injection of forged instructions. For the insurer, MitM attacks often serve as a preamble to wire fraud or identity theft: an intercepted communication allows the attacker to impersonate a senior executive to authorize a payment, creating a coverage ambiguity between the cyber policy and the directors' liability policy. The concept extends to AI in agentic architectures, where an agent may receive forged instructions through a compromised channel.
A treasurer receives by email a wire-transfer instruction signed by the CFO, confirmed by a second email. Both messages were intercepted and altered in transit by an attacker who had compromised the mail server. The cyber policy declines cover on the grounds that the loss constitutes wire fraud, covered under a separate limit at a lower cap.
MitM, MITM, interception de communication, eavesdropping, attaque par interposition