TL;DR: High-profile incidents at MGM Resorts, TransUnion, McDonald’s, UnitedHealth, and Okta show that password-centric controls still fail under social engineering and visibility gaps, according to Unixi. The real issue is not MFA alone but identity perimeter coverage, unmanaged SaaS, and shared or default credentials that leave attackers room to move.
At a glance
What this is: This is a Unixi whitepaper arguing that modern credential theft breaches succeed when MFA, SSO, and visibility controls do not fully cover the identity perimeter.
Why it matters: It matters because IAM, PAM, and identity lifecycle teams need to close the gaps between human authentication, SaaS visibility, and non-human credentials before attackers exploit them.
By the numbers:
- Gartner predicts that 85% of data breaches will involve social engineering by 2026.
- 17 minutes
👉 Read Unixi's whitepaper on preventing credential theft breaches
Context
Credential theft remains effective because identity programmes still assume authentication is the main control surface. In practice, attackers exploit help desk trust, unmanaged SaaS, shared accounts, and incomplete SSO coverage, which means the identity perimeter is wider than the control set many teams actually govern.
Unixi frames this through major breach examples where modern MFA and partial SSO did not prevent abuse of human and non-human access paths. The governance lesson is broader than any single incident: if identity visibility stops at the IdP, attackers will keep finding the systems and credentials it does not govern.
Key questions
Q: How should security teams reduce credential theft risk beyond MFA?
A: They should focus on the full identity path, not just the login event. That means hardening recovery workflows, eliminating unmanaged access paths, enforcing phishing-resistant authentication where possible, and revoking shared or stale credentials that can be abused after initial compromise.
Q: Why do partial SSO deployments increase breach risk?
A: Partial SSO leaves some applications outside central policy, logging, and offboarding controls. Attackers can use those gaps to persist or escalate access without triggering the same protections that apply to federated applications, which makes the environment harder to govern consistently.
Q: What do teams get wrong about credential abuse detection?
A: Many teams focus on the moment of theft and miss the later replay activity. Detection should look for unusual login velocity, impossible travel, credential stuffing patterns, and access after known exposure events. If monitoring only watches for phishing or malware, it can miss the stage where access is actually exploited.
Q: How do IAM and NHI teams work together on this risk?
A: They should manage human and non-human access as one governance surface. Employee authentication, service accounts, vendor credentials, and application secrets all need ownership, review, and revocation discipline, otherwise attackers will shift to whichever identity type is least visible.
Technical breakdown
Why modern MFA fails when help desk trust is the weak point
Modern MFA reduces password replay risk, but it does not stop social engineering that targets recovery flows, support desks, or account reset paths. Attackers do not always need to bypass the primary factor if they can convince an operator to reset access or approve a login path. That is why credential theft breaches often begin with identity proofing failure rather than technical compromise. In identity terms, the control broke at authentication recovery and assurance, not just at login.
Practical implication: review help desk and account recovery workflows as high-risk access paths, not administrative afterthoughts.
Partial SSO creates blind spots in SaaS and remote access governance
Partial SSO means some applications sit outside central identity controls, often through legacy portals, vendor tools, or direct login paths. Those gaps create unmanaged authentication surfaces where logging, conditional access, and lifecycle controls are inconsistent or absent. Once an attacker enters through one of those paths, the organisation loses the benefit of centralized policy enforcement. The technical problem is not SSO itself, but uneven coverage across the application estate and identity boundary.
Practical implication: map every non-federated application and remote access path that bypasses central policy enforcement.
Shared and default credentials remain a privilege escalation path
Shared credentials collapse accountability because multiple actors use the same secret, making user attribution and revocation impossible to manage cleanly. Default credentials are worse because they often persist in vendor admin accounts, legacy systems, and unowned services. In these environments, an attacker who learns one credential may inherit broad access with no clear owner to notify, rotate, or revoke. This is a classic identity governance failure, especially where access is inherited rather than individually issued.
Practical implication: inventory shared, default, and vendor admin credentials and remove them from production access paths.
Threat narrative
Attacker objective: The attacker aims to gain trusted access that can be used to move beyond the initial account and reach sensitive systems, data, or privileged workflows.
- Entry occurs through social engineering, help desk manipulation, or another human-trust path that bypasses password resistance and enters the identity workflow.
- Escalation follows when partial SSO, unmanaged SaaS, or shared credentials give the attacker broader access than the initial entry path should have allowed.
- Impact comes from account takeover, lateral movement across connected systems, and operational or financial damage at enterprise scale.
Breaches seen in the wild
- Cisco Active Directory credentials breach — Kraken ransomware group leaked Cisco Active Directory credentials.
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Credential theft is now an identity governance problem, not just an authentication problem. Modern breach patterns show that the weak point is often the control perimeter around recovery, support, and unmanaged access paths. MFA matters, but it cannot compensate for incomplete identity coverage across SaaS, remote access, and vendor-linked accounts. Practitioners should treat credential theft as a lifecycle and governance issue, not a login issue.
Partial SSO is a governance gap because it creates unowned identity territory. When some applications bypass central identity policy, the organisation cannot consistently apply assurance, logging, or offboarding. That leaves identity state fragmented across systems that do not share the same control model. Practitioners should read this as a signal that coverage, not feature count, determines whether IAM actually reduces exposure.
Shared credentials and default accounts are still a high-consequence failure mode. They collapse attribution, blur accountability, and widen blast radius when one secret is reused across systems or vendors. This is especially dangerous in admin and legacy environments where access is persistent rather than task-scoped. Practitioners should prioritise removal of these credentials before they try to optimise policy layers above them.
Identity perimeter control now has to include non-human access as well as users. The same visibility and lifecycle failures that affect humans also affect service accounts, vendor admin accounts, and application credentials. If teams only govern employee authentication, attackers will keep using the unmanaged NHI layer as the easier path. Practitioners should align IAM, PAM, and NHI governance as one programme, not separate queues.
Shadow SaaS creates the modern equivalent of an access back door. Unmanaged applications and direct login paths defeat central review even when the core IdP is hardened. This is the named concept that matters here: identity perimeter drift, where the governed boundary is smaller than the real one. Practitioners should measure how much of the application estate is outside centralized identity control.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
- Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
- For a deeper operating model, see Ultimate Guide to NHIs , Static vs Dynamic Secrets for how ephemeral credentials change the control baseline.
What this signals
Identity perimeter drift: most programmes still govern the IdP more tightly than the wider application estate. That means the next breach is more likely to come through a bypass path than through the primary authentication flow, especially where help desk recovery and direct SaaS login remain outside central control.
With 85% of organisations lacking full visibility into third-party vendors connected via OAuth apps, the attack surface now includes relationships many IAM teams do not operationally own. That is a governance problem first, and a tooling problem second, because access cannot be controlled consistently when it cannot be seen.
If your current IAM roadmap does not include service accounts, vendor credentials, and shadow SaaS in the same lifecycle model, it is incomplete. Identity security is moving toward continuous coverage, not discrete authentication projects.
For practitioners
- Map the real identity perimeter Inventory every authentication path that bypasses central SSO, including legacy portals, vendor tools, and direct SaaS logins. Classify each path by ownership, logging coverage, and offboarding ability so gaps are visible before attackers find them.
- Harden help desk recovery workflows Treat account recovery, reset, and support escalation as privileged actions. Require phishing-resistant verification, stronger operator checks, and audit trails for every reset so social engineering cannot convert support trust into account takeover.
- Eliminate shared and default credentials Find shared admin passwords, vendor accounts, and legacy defaults across production systems and replace them with individually attributable access. Where replacement is not immediate, isolate them behind explicit approval and continuous monitoring.
- Extend governance to non-human identity Bring service accounts, API keys, and vendor admin credentials into the same lifecycle, review, and revocation process used for employees. That makes the control model consistent when attackers target machine or third-party access.
Key takeaways
- Credential theft succeeds when attackers exploit the parts of identity governance that sit outside the login screen, including help desk workflows, unmanaged SaaS, and shared access paths.
- The evidence points to a structural visibility problem, with central identity controls often covering less of the real environment than teams assume.
- Practitioners should extend IAM, PAM, and NHI governance across the whole identity perimeter before attackers use the gaps as entry points.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Identity proofing and access control are central to the recovery and SSO gaps in this whitepaper. |
| NIST SP 800-53 Rev 5 | IA-2 | Authentication assurance is directly relevant where MFA and recovery paths were bypassed. |
| NIST Zero Trust (SP 800-207) | The article is about reducing trust in implicit identity paths across applications and support flows. | |
| OWASP Non-Human Identity Top 10 | NHI-03 | Shared and default credentials are a central non-human identity risk in the article. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0001 , Initial Access | The breach patterns rely on credential theft and initial access through social engineering. |
Review authentication and recovery flows against IA-2 and strengthen assurance for high-risk access changes.
Key terms
- Identity Perimeter: The identity perimeter is the access boundary defined by who or what is requesting entry, not by where the request comes from. In zero trust, it is the point where authentication, authorization, and risk context decide whether a caller can proceed.
- Partial SSO Coverage: Partial SSO coverage means some applications and workflows are federated while others still use local or manual authentication paths. In practice, it creates a split control environment where policy, logging, and lifecycle management do not apply evenly to the whole estate.
- Shadow SaaS: Shadow SaaS is the set of unauthorised or unreviewed software-as-a-service tools used outside central security governance. These applications often bypass normal identity controls, making them difficult to inventory, monitor, and harden against credential-based abuse.
- Shared credentials: Shared credentials are passwords, tokens, or access secrets used by more than one person or system. They weaken attribution and revocation because no single identity owns the secret cleanly, which increases blast radius when the credential is exposed or abused.
What's in the full article
Unixi's full whitepaper covers the operational detail this post intentionally leaves for the source:
- The incident-by-incident breakdown of how each breach chain unfolded across help desk, SSO, and account recovery paths.
- The control framework for replacing partial SSO with broader identity perimeter coverage across managed and unmanaged applications.
- The specific handling model for vendor admin accounts, shared credentials, and legacy systems that still resist federation.
- The practical recommendations for enforcing phishing-resistant, device-bound authentication across the full environment.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM and identity governance programme, it is worth exploring.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org