A type of man-in-the-middle attack in which a cybercriminal employs various methods to meddle in an open data channel to steal a connection ID and gain unauthorized access to the target system. Web applications that store a unique session key on the user side are most vulnerable to session hijacking.