Attackers are increasingly leveraging compromised identities to gain initial access to enterprise environments, with identity weaknesses playing a role in nearly 90% of incidents investigated by Unit 42, a cybersecurity research and incident response team. This trend is highlighted in the 2026 Unit 42 Global Incident Response Report, which also indicates that 65% of initial access activities involve identity-based techniques.
The report identifies credential theft, multifactor authentication (MFA) manipulation, session hijacking, and social engineering as highly effective methods for attackers to breach systems. These tactics are often employed through phishing campaigns, social engineering calls, MFA fatigue attacks, exploitation of compromised third-party accounts, and misuse of help desk processes.
Once initial access is gained, attackers typically establish persistence, elevate privileges, and move laterally across various environments. This malicious activity often mimics legitimate administrative behavior, allowing it to remain undetected long enough for attackers to broaden their foothold before security teams fully recognize the scope of the incident.
Threat groups like Muddled Libra, also known as Scattered Spider, exemplify this approach by heavily relying on social engineering and identity abuse. The 2026 Unit 42 Global Incident Response Report notes that 87% of incidents span multiple attack surfaces, meaning an initial identity compromise can quickly escalate into a multi-domain investigation requiring defenders to correlate activity across the entire environment.
The ultimate objectives of these identity-driven compromises vary, including ransomware deployment, data theft, financial fraud, or establishing long-term persistence. Regardless of the specific goal, identity compromise frequently serves as the foundational step for broader attacker objectives.
Security controls within organizations often generate warning signs of these activities, but without automated correlation, these signals can appear as low-priority isolated events. This allows attackers to expand their access before defenders can recognize the full extent of the incident.
To counter these evolving threats, security leaders are advised to prioritize identity context by correlating identity activity with telemetry from endpoints, cloud services, SaaS applications, and networks. This provides the behavioral context necessary to differentiate legitimate user activity from compromised accounts. Reducing manual investigation by consolidating telemetry and investigations into a unified view is also crucial, as it minimizes the need for analysts to pivot between disconnected tools, enabling faster and more confident responses.
Continuous improvement of detection mechanisms is also emphasized, requiring regular refinement of detections, correlation rules, and response playbooks to adapt to evolving attacker techniques. Furthermore, dedicating time to threat hunting can help uncover credential abuse, privilege escalation, and hidden persistence before they escalate into larger incidents.






