Session hijacking is the takeover of a logged-in account by stealing or reusing its session token, usually a cookie, so no password or second factor is needed.
Read the full article on PPC Land →