Identity SecurityIntermediateThreat4 validated evidence records

Identity-Driven Intrusion

Also known as: Identity-based attack, Identity compromise

30 sec

An intrusion in which stolen, manipulated, over-privileged, or otherwise abused identities become the attacker’s primary path into and through an environment.

Know

What is Identity-Driven Intrusion?

Identity-driven intrusions rely on valid or apparently valid access rather than obvious malware. Attackers may steal credentials or tokens, socially engineer help desks, exploit weak MFA, abuse excessive permissions, compromise service accounts, or take over SaaS sessions. Once authenticated, their activity can look like normal business use.

Why it matters

Identity is one of the defining attack surfaces of 2026. Unit 42 reported identity weaknesses played a material role in nearly 90% of its investigations, and Google Cloud reported identity issues drove initial access in 83% of major cloud and SaaS incidents it analyzed.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationMeasured outcome

Identity weaknesses played a material role in nearly 90% of Unit 42 investigations

2026-02-17Palo Alto Networks Unit 42Cross-sector

Unit 42's 2026 Global Incident Response Report says identity was involved in nearly 90% of investigated incidents and that 65% of initial access was driven by identity-based techniques, including phishing, credential misuse, and permission abuse.

Why this is evidence

This frontline incident-response data validates identity as a primary modern attack surface rather than a supporting control category.

See the source — Palo Alto Networks Unit 42: 2026 Global Incident Response Report
Technical ValidationMeasured outcome

Cloud and SaaS incidents were dominated by identity compromise and data theft

2026-H1Google Cloud / MandiantCloud and SaaS

Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.

Why this is evidence

The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.

See the source — Google Cloud: Cloud Threat Horizons Report H1 2026
Technical ValidationOperational validation

Large-scale AiTM phishing targeted more than 35,000 users across 13,000 organizations

2026-05-04Microsoft Defender Research and Microsoft Threat IntelligenceCross-sector

Microsoft analyzed a multi-stage phishing campaign observed in April 2026 that targeted more than 35,000 users across more than 13,000 organizations and ultimately used adversary-in-the-middle infrastructure to capture authentication tokens.

Why this is evidence

This validates that session-token compromise and AiTM phishing are operating at enterprise scale and can bypass non-phishing-resistant MFA even when the user sees a legitimate authentication experience.

See the source — Microsoft Security: Breaking the code: Multi-stage 'code of conduct' phishing campaign leads to AiTM token compromise
Technical ValidationMeasured outcome

CrowdStrike reported AI-enabled adversary operations up 89% year over year

2026-02-24CrowdStrikeCross-sector

CrowdStrike's 2026 Global Threat Report says AI-enabled adversary operations increased 89% year over year, average eCrime breakout time fell to 29 minutes, the fastest observed breakout was 27 seconds, and attacks increasingly traversed identity, SaaS, cloud, and unmanaged edge environments.

Why this is evidence

The report validates both the growing operational use of AI by attackers and the shrinking time defenders have to detect and contain intrusions.

See the source — CrowdStrike: 2026 Global Threat Report: AI Accelerates Adversaries and Reshapes the Attack Surface

Understand the mechanics

How it works

  1. 1

    Obtain or manipulate a human or machine identity.

  2. 2

    Authenticate through a legitimate access path.

  3. 3

    Use valid permissions to discover data, systems, roles, and trust relationships.

  4. 4

    Escalate privileges or hijack additional identities.

  5. 5

    Move through SaaS, cloud, endpoints, and applications while blending into normal activity.

  6. 6

    Exfiltrate data, commit fraud, deploy malware, or establish persistence.

Practice

What to watch for

  • Sign-ins from unusual devices, networks, or locations
  • Unexpected MFA or device-enrollment events
  • New OAuth grants or application consents
  • Privilege changes that do not match business activity
  • Service-account or API-key use outside normal patterns
  • Large or unusual data access by valid accounts

Perform

What to do

  1. 1

    Treat the identity as compromised until proven otherwise.

  2. 2

    Revoke active sessions, refresh tokens, API keys, and suspicious device registrations.

  3. 3

    Reset or re-establish authentication using a trusted process.

  4. 4

    Review permissions, OAuth grants, mailbox rules, and downstream access.

  5. 5

    Hunt for activity performed with the compromised identity across SaaS, cloud, endpoint, and network logs.

How to reduce the risk

  • Phishing-resistant MFA
  • Conditional access
  • Least privilege
  • Privileged access management
  • Short-lived credentials
  • Machine-identity governance
  • Session and token monitoring
  • Identity threat detection and response

Business impact

  • Data theft
  • SaaS compromise
  • Cloud takeover
  • Financial fraud
  • Privilege escalation
  • Difficult-to-detect lateral movement

What different roles should do

Employee

  • Never approve unexpected authentication requests
  • Report identity-verification requests that feel unusual

IT / Identity

  • Harden recovery and enrollment workflows
  • Monitor risky sign-ins and token use

Security

  • Correlate identity telemetry across cloud, SaaS, endpoint, and email

Framework & standards context

  • MITRE ATT&CK Valid Accounts
  • NIST CSF 2.0 Protect / Detect / Respond

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02