Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Learn how AiTM phishing reverse-proxies steal live session tokens and how Doppel takes down their infrastructure to protect your financial services brand and customers.

Imagine it’s 7:00 AM on a Tuesday. A longtime customer of your retail bank receives an urgent text message (opens in new tab) warning them about an unauthorized $500 transfer.
Panicked and half-awake, they tap the link provided.
The link opens a login page that looks identical to your official banking portal. There’s a crisp logo, familiar font, and the URL looks close enough to fool a groggy brain, so they type in their username and password.
Immediately, your bank's legitimate backend sends an SMS code to their phone. The customer types the code into the portal. The page loads, politely informing them that their account is secure and the transfer was blocked. They breathe a sigh of relief and go back to drinking their coffee.
What they don’t realize is that they never actually logged into your bank.
In reality, they logged into an invisible middleman. The customer just handed over their credentials, and the attacker walked away with a live, fully authenticated session token.
The cybercriminal is now wandering freely through the customer's checking account, entirely bypassing your multi-factor authentication (MFA) (opens in new tab).
This is an adversary-in-the-middle (AiTM) attack (opens in new tab), the new driving force behind financial fraud that’s tearing down the perimeter of open banking (opens in new tab).
Here’s why your legacy MFA isn't protecting your financial brand, and how you can stop these attackers before they send a single text message.
Financial services, like most industries, treated MFA as the be-all and end-all for several years. Customers thought that as long as a six-digit code was sent to their phone, or an authenticator app generated a time-based PIN, their money was safe.
But cybercriminals are pragmatic business operators. When they realized they couldn’t easily brute-force passwords anymore, they didn't pack up and go home. They realized they could just trick the customer into opening the ‘door’ for them.
MFA alone isn’t a silver bullet for banking apps in 2026. In fact, relying solely on standard MFA to protect your customer base is a recipe for a massive, highly publicized breach.
Why? Because credential harvesting today is entirely focused on capturing live session tokens (opens in new tab) in real time.
In phishing’s early days, attackers built fake, static websites. A user typed in their password, the fake site saved it in a database, and the attacker tried to log in later. That method fails instantly against MFA because the attacker doesn't have the real-time code.
AiTM throws that old playbook out the window. Now, syndicates use sophisticated reverse-proxy toolkits (like Evilginx (opens in new tab)).
Instead of a static fake website, the attacker sets up a dynamic proxy server that sits right in between the customer and your actual banking infrastructure. It acts as an invisible tollbooth.
Here’s how this heist goes down:
All the while, the attacker looks exactly like the legitimate customer who just passed an MFA check.
An AiTM attack is a nightmare for a standalone retail bank (opens in new tab), but it becomes a catastrophic, systemic threat when you introduce the realities of open banking.
Modern financial services don’t operate in silos. The entire premise of open banking is interoperability. Customers expect their primary bank account to seamlessly connect to their budgeting apps, crypto wallets, investment portfolios, and peer-to-peer payment platforms like Venmo (opens in new tab) or Zelle (opens in new tab).
This interconnected ecosystem is powered by APIs and OAuth connections.
When a threat actor uses an AiTM reverse-proxy to steal a session token, they’re gaining access to the epicenter of the customer's financial life.
With a live session token, attackers can exploit the open banking ecosystem in terrifying ways:
A single stolen token is the skeleton key to the entire financial supply chain.
When a financial institution realizes their customers are being targeted by an AiTM campaign, the standard reaction is entirely defensive.
The SOC waits for a customer to complain about a fraudulent charge or report a sketchy text message. An analyst investigates, identifies the lookalike domain (like secure-login-yourbank.com), and adds it to a blocklist.
This is like trying to put out a forest fire with a squirt gun.
By the time your SOC blocks the domain, the attacker has already stolen dozens of tokens, drained the accounts, and spun up three brand new lookalike domains.
Threat syndicates automate their infrastructure deployment, meaning they register new domains, provision SSL certificates, and spin up fresh reverse-proxy servers in minutes. If you’re waiting for the phishing lure to hit your customer's phone before you take action, you have already lost the battle.
Stop playing defense inside the customer's inbox and start playing offense at the infrastructure level.
Doppel’s agentic AI-native platform (opens in new tab) for social engineering defense (opens in new tab) continuously monitors the earliest stages of the threat lifecycle. We hunt for the infrastructure before the attack is armed.
When a threat syndicate decides to target your financial brand with an AiTM reverse-proxy, they leave a digital footprint. They have to register a typosquatted domain, configure DNS records to route traffic to their proxy server, and request SSL certificates to make the fake site look secure.
Doppel (opens in new tab) sees all of it.
The platform detects the staging environments of AiTM infrastructure at the registrar and DNS level. We identify the malicious lookalike domains the exact moment they’re registered, long before the attacker sends a single SMS lure to your customers.
And when Doppel identifies a staged AiTM proxy targeting your brand, we don’t just send you an alert to add to a blocklist. We execute an automated, machine-speed takedown.
Our AI autonomously navigates the complex global takedown process, interfacing directly with domain registrars, hosting providers, and DNS registries. We burn the attacker's infrastructure to the ground before they ever get the chance to capture a live session token.
To protect the perimeter of modern open banking, financial institutions need to shift from reactive triage to proactive disruption.
Here’s a quick look at how the legacy approach to brand protection (opens in new tab) compares to an agentic, infrastructure-focused defense:
Defensive capability | Legacy brand protection | Agentic AI-native defense |
detection timing | Relies on customer reports after the phishing lure has been deployed | Detects AiTM staging environments at the DNS/registrar level before launch |
MFA posture | Assumes SMS or Authenticator app codes are sufficient to stop account takeovers | Recognizes that reverse-proxies steal live tokens, requiring infrastructure takedowns |
Remediation speed | Manual abuse reporting that takes days or weeks to process | Automated API-driven takedowns that neutralize the threat at machine speed |
Ecosystem impact | Leaves the open banking ecosystem vulnerable to token-based API pivoting | Destroys the staging ground, protecting both the primary bank and connected apps |
The evolution of financial fraud has rendered the old security playbooks obsolete.
As long as we rely on the illusion that standard MFA is enough to protect our customers, threat actors will continue to set up invisible tollbooths, steal live session tokens, and drain accounts.
In the era of open banking, your security strategy can’t begin and end at the login screen. You have to aggressively defend your brand's perimeter across the open web.
By detecting AiTM staging environments at the registrar level and executing automated takedowns before the first lure is sent, Doppel ensures that when your customer logs in on a Tuesday morning, they are actually logging in to you.
Ready to defend your financial brand from advanced AiTM phishing? Get a demo (opens in new tab) to see how Doppel’s agentic AI detects staging infrastructure and executes automated takedowns at machine speed.