home/glossary/Man-in-the-middle attack

Man-in-the-middle attack

nounverified·updated May 9, 2026

A form of active wiretapping attack in which the attacker intercepts and selectively modifies communicated data to masquerade as one or more of the entities involved in a communication association.

polysemousMWENISTIR 7298: Glossary of Key Information Security Terms, Revision 2

Senses

ISACA Cybersecurity Glossary

An attack strategy in which the attacker intercepts the communication stream between two parts of the victim system and then replaces the traffic between the two components with the intruder’s own, eventually assuming control of the communication

Federal Financial Institutions Examination Council (FFIEC) IT Examination Handbook Infobase, Glossary

Places the attacker's computer in the communication line between the server and the client. The attacker's machine can monitor and change communications.

NISTIR 7298: Glossary of Key Information Security Terms, Revision 2

An attack on the authentication protocol run in which the Attacker positions himself in between the Claimant and Verifier so that he can intercept and alter data traveling between them.

Classifications

Entity Type

Threat90%rule-basedr:entity.threat.attack.v1
?unassignedlast reviewed

Sensitivity

unclassified

Information Class

unclassified

Variants

acronym
MitM
plural
Man-in-the-middle attacks
possessive
Man-in-the-middle attack's
pluralpossessive
Man-in-the-middle attacks'