Identity-based attacks persist because attackers adapt faster than many defensive programmes and target human behaviour directly. Phishing, social engineering, MFA bypass attempts, and credential theft exploit trust relationships that technology alone cannot remove. As controls improve, adversaries shift to the weakest operational link, especially help desks, mobile channels, and privileged identity workflows where a single compromise can unlock broader access.
Why identity attacks keep winning even as controls improve
Identity attacks persist because the control surface keeps shifting, not because defenders are standing still. As phishing filters, conditional access, and passwordless options improve, attackers move to the places where trust is still exercised by people and processes: help desks, approvals, recovery paths, session abuse, and delegated access. The breach often begins with a legitimate-looking request, then expands through identity and access paths that are easy to trust but hard to constrain.
That is why the problem survives technology progress. Modern controls can reduce bulk password theft, yet they do not remove the need for someone to approve access, reset an account, accept a token, or respond to a “normal” business exception. Attackers look for the control that is technically present but operationally porous. In practice, they exploit the mismatch between a strong policy on paper and a workflow that still allows one well-placed compromise to unlock broader access.
What improves, and what attackers adapt to next
Improved controls usually compress the obvious attack paths first, such as reused passwords and unsophisticated credential stuffing. In response, adversaries shift toward tactics that attack trust directly: social engineering, MFA fatigue or bypass, token theft, cookie theft, help-desk impersonation, and privilege escalation through poorly governed recovery or delegation. Once they obtain a valid session or a trusted approval, they no longer need to “break in” in the traditional sense.
This is why identity defence must be measured by more than authentication strength. Coverage, recovery, and privilege boundaries matter just as much as MFA adoption. If a workforce can still be convinced to approve a prompt, a support process can still be socially engineered, or a privileged workflow can still be abused, the environment remains breachable even when the front door looks stronger. A useful reference point is the 52 NHI breaches analysis, which shows how compromise frequently turns on exposed secrets, excessive privilege, and lateral movement after initial access.
The same pattern appears in broader identity failures, where a single compromised trusted account or provider relationship can produce disproportionate blast radius. That is why identity attacks continue to dominate: the attacker is not always trying to defeat the strongest control, only the weakest operational step that still confers authority.
Risk and Threat Considerations
Identity-based attacks remain high-impact because they turn legitimate trust into an exploitation path. The operational risk is not just account takeover, but rapid expansion from one compromised credential, token, or approval path into broader privilege, data access, or administrative control.
Failure mechanism: Defenders harden authentication while leaving recovery, help-desk validation, delegated approval, and session handling with too much implicit trust. Attackers then use phishing, vishing, token theft, or process manipulation to obtain a valid foothold that bypasses perimeter-style controls.
Impact: Once a trusted identity path is compromised, the attacker can impersonate a legitimate actor, move laterally, and trigger actions that look authorised. That makes detection slower, containment harder, and blast radius larger than in attacks that rely on noisy malware alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Secrets and Credential Management | Credential theft and secret abuse are central to identity-based breaches. |
| NHI-03 — Privilege Management | Excessive privilege turns one identity compromise into broad access. | |
| NHI-06 — Lifecycle and Revocation | Slow revocation lets stolen identity material stay usable after compromise. | |
| Recommendation — Rotate secrets aggressively and remove long-lived credentials from exposed workflows. Enforce least privilege and remove standing access from high-risk identities. Shorten credential lifetimes and verify revocation actually propagates. | ||
| CIS Controls v8 | 6 — Access Control Management | Identity attacks succeed when access paths are too broad or too easy to reuse. |
| 5 — Account Management | Account lifecycle gaps and weak recovery processes enable takeover and misuse. | |
| Recommendation — Restrict access paths to only the privileges each account needs. Continuously inventory accounts and remove stale or unnecessary access. | ||
| MITRE ATT&CK | T1586 — Compromise Accounts | The question centers on adversaries abusing legitimate identities to breach environments. |
| T1110 — Brute Force | Attackers often combine guessing, credential stuffing, and MFA abuse to gain access. | |
| Recommendation — Detect and hunt for account compromise indicators across login and recovery channels. Monitor for repeated authentication failures and automated credential abuse patterns. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | Identity-based breaches are fundamentally about proving and limiting access. |
| Recommendation — Tighten identity proofing, authentication, and access enforcement across critical workflows. | ||
Practitioner Guidance
What to verify: Test the entire identity journey, not just login. If a help desk, approval chain, or recovery channel can reissue access without strong, independent verification, that workflow is part of the attack surface and should be treated as such.
What good looks like: Strong identity defence shows up as narrow privilege, short-lived access, resistant recovery processes, and visible approvals that can be traced back to a real business need. If those conditions are missing, better authentication alone will not materially change breach likelihood.
Practitioner takeaway: Identity attacks dominate when organisations overestimate the protection provided by authentication technology and underestimate the value of trust-bearing workflows. The decisive control is not only stronger sign-in, but tighter authority around every path that can legitimately grant, restore, or extend access.
Related resources from NHI Mgmt Group
- Why do human decisions continue to drive breaches even when technical controls are strong?
- Why do upstream gateways and signature based controls miss so many modern email and identity attacks?
- Why do legacy applications and siloed identity controls increase the risk of identity-based attacks in mixed environments?
- How can organisations detect whether identity-based attacks are slipping past controls?