Articles, News and Updates

Attackers do not need to break in, they simply log in

Written by Tom Moester | Jul 23, 2026 7:58:09 AM

This is not an exception, but a structural pattern. Our 2026 Trend Report shows that in many incidents, attackers make use of existing accounts and identity-related attack techniques. The abuse of legitimate accounts has long played a role in attacks, not just as part of the attack, but as the starting point. According to IBM, around 30% of global incidents are now identity-based. We consistently see this pattern in incident response cases as well: attackers gain access through accounts and build their attack from there.

Access without a break-in

Through phishing, infostealers, and other techniques, attackers obtain login credentials. This gives them relatively easy access to systems without having to exploit technical vulnerabilities. That is precisely what distinguishes these attacks from more traditional ones: the activity appears legitimate, which often means it goes undetected.

Techniques such as token abuse or session hijacking reinforce this effect: even when an organization uses MFA (multi-factor authentication), an active session can be taken over without the need to authenticate again. In practice, this means that an attacker with stolen credentials or a hijacked session can log in seamlessly and move through the environment within the existing permission structure, without being immediately recognized as suspicious.

Identity as an attack surface

For a long time, security was focused on protecting systems and networks. Today, the attack surface is increasingly centered on identity. Anyone with valid credentials, sessions, or tokens has direct access to systems and data in many environments. This is reinforced by the way identity environments are configured. Permissions and roles accumulate over time, accounts retain access to systems they no longer need, and integrations increase the number of access points.

The result is that the distinction between legitimate use and abuse becomes blurred. An attacker who logs in with an existing account initially behaves like a regular user. Only later, when privileges are expanded, systems are explored, or unusual data is accessed, does behaviour begin to deviate. It is precisely this phase that determines the impact, yet it is difficult to detect without a coherent view of identity, sessions, permissions, and behaviour.

MFA is not the end point

MFA is often seen as an important line of defense. That is justified, but it is not the end point. Now that MFA has been widely adopted, attackers are actively looking for ways to bypass it. Techniques such as phishing, MFA fatigue (bombarding users with push notifications), and man-in-the-middle attacks make it possible to abuse or circumvent MFA processes. In addition, MFA is mainly focused on the moment of login, while sessions and tokens are often monitored only to a limited extent afterward.

The result is a persistent misconception: that access is sufficiently protected once MFA has been implemented. In reality, the risk shifts to what happens after login: the abuse of sessions, the expansion of privileges, and movement within the environment.

The attack begins after login

In incident response cases, we see that attacks rarely stop at access. Once an attacker is inside, the real process begins: expanding privileges, exploring systems, and moving through the environment. This often happens through existing accounts and permission structures. Lateral movement (jumping from system to system), privilege escalation (obtaining more rights), and access to sensitive systems all take place within an apparently legitimate context and across multiple systems.

The problem is not that these signals are absent, but that they are not seen in context. As a result, an attack can be visible without actually being recognized. The impact of an incident is therefore determined not only by how access is gained, but above all by what an attacker can do inside an environment afterwards.

An invisible problem

As with other forms of detection, visibility is crucial. In many incidents, there is a lack of complete and consistent insight into identity-related behaviour. Logs are incomplete, monitoring is fragmented, and behaviour is not analyzed holistically. This creates a situation in which attacks are technically visible, but not recognized as such. As a result, attackers can move through the environment for longer periods and cause greater damage.

From access to behaviour

At the heart of the problem is not the method of access, but how attackers are able to exploit that access. As long as organizations focus mainly on preventing unauthorized access, a large part of the attack path will remain out of sight.

Effective protection therefore requires a shift: from a sole focus on the front door (authentication) to insight into what happens inside after a successful login (behaviour). It is not just about controlling who gets access, but also understanding what happens next - across systems, sessions, and permissions.

Without visibility, there is no control

As long as organizations do not have full visibility into how identities are used within their environment, identity-based attacks will remain difficult to detect, regardless of the preventive security measures in place. Identity is therefore not just an access mechanism, but a primary domain for security, detection, and control. Without insight into that use and behaviour, control remains limited. And without control, identity abuse remains one of the most effective attack routes.