Know
What is Identity-Driven Intrusion?
Identity-driven intrusions rely on valid or apparently valid access rather than obvious malware. Attackers may steal credentials or tokens, socially engineer help desks, exploit weak MFA, abuse excessive permissions, compromise service accounts, or take over SaaS sessions. Once authenticated, their activity can look like normal business use.
Why it matters
Identity is one of the defining attack surfaces of 2026. Unit 42 reported identity weaknesses played a material role in nearly 90% of its investigations, and Google Cloud reported identity issues drove initial access in 83% of major cloud and SaaS incidents it analyzed.
Evidence, not hype
Validated in the real world
Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.
Identity weaknesses played a material role in nearly 90% of Unit 42 investigations
Unit 42's 2026 Global Incident Response Report says identity was involved in nearly 90% of investigated incidents and that 65% of initial access was driven by identity-based techniques, including phishing, credential misuse, and permission abuse.
This frontline incident-response data validates identity as a primary modern attack surface rather than a supporting control category.
Cloud and SaaS incidents were dominated by identity compromise and data theft
Google Cloud reports identity issues were used for initial access in 83% of major cloud and SaaS incidents it analyzed, while data theft was targeted in 73%. The report also documents vishing, help-desk manipulation, SaaS token abuse, living-off-the-cloud behavior, and compromised third-party trust.
The report connects identity, SaaS, cloud, social engineering, and trusted integrations into a single modern intrusion pattern rather than isolated threat categories.
Large-scale AiTM phishing targeted more than 35,000 users across 13,000 organizations
Microsoft analyzed a multi-stage phishing campaign observed in April 2026 that targeted more than 35,000 users across more than 13,000 organizations and ultimately used adversary-in-the-middle infrastructure to capture authentication tokens.
This validates that session-token compromise and AiTM phishing are operating at enterprise scale and can bypass non-phishing-resistant MFA even when the user sees a legitimate authentication experience.
CrowdStrike reported AI-enabled adversary operations up 89% year over year
CrowdStrike's 2026 Global Threat Report says AI-enabled adversary operations increased 89% year over year, average eCrime breakout time fell to 29 minutes, the fastest observed breakout was 27 seconds, and attacks increasingly traversed identity, SaaS, cloud, and unmanaged edge environments.
The report validates both the growing operational use of AI by attackers and the shrinking time defenders have to detect and contain intrusions.
Understand the mechanics
How it works
- 1
Obtain or manipulate a human or machine identity.
- 2
Authenticate through a legitimate access path.
- 3
Use valid permissions to discover data, systems, roles, and trust relationships.
- 4
Escalate privileges or hijack additional identities.
- 5
Move through SaaS, cloud, endpoints, and applications while blending into normal activity.
- 6
Exfiltrate data, commit fraud, deploy malware, or establish persistence.
Practice
What to watch for
- Sign-ins from unusual devices, networks, or locations
- Unexpected MFA or device-enrollment events
- New OAuth grants or application consents
- Privilege changes that do not match business activity
- Service-account or API-key use outside normal patterns
- Large or unusual data access by valid accounts
Perform
What to do
- 1
Treat the identity as compromised until proven otherwise.
- 2
Revoke active sessions, refresh tokens, API keys, and suspicious device registrations.
- 3
Reset or re-establish authentication using a trusted process.
- 4
Review permissions, OAuth grants, mailbox rules, and downstream access.
- 5
Hunt for activity performed with the compromised identity across SaaS, cloud, endpoint, and network logs.
How to reduce the risk
- Phishing-resistant MFA
- Conditional access
- Least privilege
- Privileged access management
- Short-lived credentials
- Machine-identity governance
- Session and token monitoring
- Identity threat detection and response
Business impact
- Data theft
- SaaS compromise
- Cloud takeover
- Financial fraud
- Privilege escalation
- Difficult-to-detect lateral movement
What different roles should do
Employee
- Never approve unexpected authentication requests
- Report identity-verification requests that feel unusual
IT / Identity
- Harden recovery and enrollment workflows
- Monitor risky sign-ins and token use
Security
- Correlate identity telemetry across cloud, SaaS, endpoint, and email
Framework & standards context
- MITRE ATT&CK Valid Accounts
- NIST CSF 2.0 Protect / Detect / Respond
Source transparency
Authoritative sources
- Palo Alto Networks Unit 42: 2026 Global Incident Response Report ↗
- Google Cloud: Cloud Threat Horizons Report H1 2026 ↗
Last reviewed: 2026-09-02