Session theft scams that exploit an already authenticated user | Dead Internet Theory
Dead Internet Theory: Session theft targets the authenticated state a browser already holds after login. Microsoft and Google have documented attacks in which stolen session cookies or tokens let attackers impersonate users without repeating the normal sign-in flow.