Recently major news stories have come out detailing attackers using stolen cookies or token to facilitate their access. Everyone has the same question, why are they focusing on cookies? I think it is important to understand how threat actors have evolved their access attacks over the years. We will start with port scanning for open connections through to the abuse of key signing for token creation. We will discuss how cyber security has evolved to tackle these vectors, and how this forced the threat actors to pivot to new attacks and vectors. Finally, we will discuss the shift to token and cookie abuse, and where the security is successful in detecting and blocking these attacks. I will close out the talk with looking at how identity and security products need to continue to evolve to take on this latest threat.