By NHI Mgmt Group Editorial TeamBased on StrongDM: “35+ Alarming Data Breach Statistics for 2026” (September 15, 2025)

TL;DR: Identity failures still dominate breach paths, with 22% of incidents involving stolen credentials overall and 88% of basic web app attacks using them, while organisations needed 241 days on average to detect and contain breaches, according to StrongDM’s 2025 breach statistics. The control gap is not perimeter strength but the combination of credential governance, detection speed, and third-party access control.


At a glance

What this is: This is StrongDM’s compilation of 2025 breach statistics showing that stolen credentials, slow detection, and third-party exposure remain the main ways attackers keep access long enough to cause damage.

Why it matters: It matters because IAM, PAM, NHI, and access governance teams need to treat credential abuse and delayed containment as programme-level failures, not isolated incident symptoms.

By the numbers:

  • In 2025, the mean time to identify was 181 days and the mean time to contain was 60 days, for 241 days end-to-end.
  • In 2025, 22% of breaches involved stolen credentials overall.
  • In basic web app attacks, 88% used stolen credentials.
  • The average cost of a data breach was $4.44 million.

Context

Data breach statistics are only useful if they point to the controls that are actually failing. In this article, the recurring pattern is identity compromise, especially stolen credentials, weak authentication, and third-party access that survives long after it should have been removed.

For IAM and NHI programmes, the important question is not whether attackers target large or small organisations. It is whether access control, detection, and vendor governance are built to limit how long stolen or inherited credentials can stay useful once an adversary is inside.


Key questions

Q: What breaks when compromised credentials are still accepted by identity systems?

A: When compromised credentials are still accepted, detection becomes a post-exploitation signal rather than a control. Attackers can authenticate through legitimate paths, evade obvious alarms, and move before containment begins. That is why the real failure is not only credential theft, but delayed invalidation of trust after exposure.

Q: Why do breaches with valid credentials stay active for so long?

A: Because detection and containment are separate problems, and both can fail. Teams may discover suspicious activity late, but still need time to trace the identity, revoke access, and clean up connected accounts or sessions. Long dwell time means the attacker keeps a legitimate-looking path longer, which increases data loss, persistence, and the cost of recovery.

Q: What are the signs that third-party access controls are failing in practice?

A: Common warning signs include broad or stale tokens, undocumented permission changes, open endpoints, inconsistent documentation, and vendor activity that blends into routine system traffic. Another signal is when teams cannot clearly explain who owns an integration or what happens if access must be revoked quickly. Those are usually indicators that governance has drifted.

Q: How do IAM teams reduce blast radius after a cloud credential exposure?

A: IAM teams reduce blast radius by combining least privilege, short-lived credentials, and fast revocation with continuous monitoring. They should also verify whether the exposed identity can enumerate storage, assume roles, or impersonate analytics users. If the access scope is broad, the response must include permission reduction, not only rotation.


Technical breakdown

Stolen credentials turn authentication into an entry point

When attackers obtain valid credentials, they do not need to defeat perimeter controls in the traditional sense. Authentication succeeds because the system is asked to trust a legitimate secret, even if the holder is malicious. That is why stolen passwords, reused passwords, and credential stuffing remain so effective. The problem is not only initial access. Valid credentials often inherit broad access paths, and those paths are difficult to distinguish from normal activity until the attacker starts moving laterally or collecting data. This is an identity problem first and a network problem second.

Practical implication: treat credential theft as a trust failure in authentication, not just a detection event.

Long dwell times expand blast radius

Mean time to identify and mean time to contain describe two different governance failures. Identification is the delay before teams realise access has been abused. Containment is the delay before the abused access is actually neutralised. Together, they define how long an attacker can operate with legitimate-looking access. In identity terms, every extra day increases the odds that standing privileges, session tokens, and connected accounts will be used for collection, backdoors, or further compromise. Fast response matters, but only if the identity layer can also revoke access cleanly and at scale.

Practical implication: measure how quickly compromised identities can be located, revoked, and isolated in practice.

Third-party access is still the hidden breach path

Roughly 30% of breaches involving third-party vendors shows that identity risk does not stop at the organisation boundary. Vendor accounts, shared access paths, and inherited trust relationships often outlive the business context that created them. That creates a governance gap: access is still active even when the relationship has changed, or when the third party itself is compromised. In NHI terms, the issue is lifecycle control. In human IAM terms, it is delegated trust without enough offboarding discipline. The control failure is not just who got in, but whose access continued to exist after its purpose ended.

Practical implication: review third-party access as a lifecycle problem, not a one-time onboarding control.


Threat narrative

Attacker objective: The attacker wants prolonged, low-friction access to sensitive systems and data while remaining hard to distinguish from legitimate users.

  1. Entry occurs through stolen or reused credentials, or through a compromised third party that already has trusted access.
  2. Credential access is trivial because the attacker is using a valid secret, so authentication accepts the session as legitimate.
  3. Escalation follows when the attacker leverages broad permissions, backdoors, or connected accounts to widen access and persistence.
  4. Impact arrives when the attacker collects sensitive data, creates long-term access, or drives regulatory and financial loss.

NHI Mgmt Group analysis

Credential reuse remains the most practical breach primitive: The article’s numbers show that stolen credentials still dominate real-world intrusion paths, which means identity controls are failing at the point of trust. Password hygiene, reuse prevention, and privileged access limits are not background issues; they are the front line. When 88% of basic web app attacks use stolen credentials, the control question becomes whether authentication is actually proving possession, not merely recognising a known secret.

Detection speed is now an identity governance issue: A 241-day breach lifecycle is long enough for access rights, vendor trust, and dormant sessions to be abused repeatedly. This is not only a SOC problem. It is also a governance problem because identity systems often cannot answer quickly which accounts were active, which were shared, and which trust relationships still existed during the exposure window. Practitioners should read dwell time as a measure of identity programme weakness.

Third-party access without lifecycle offboarding is a recurring failure mode: The article’s third-party breach share shows that delegated access keeps outliving the business need that justified it. That is a lifecycle failure, not a procurement issue. Once a vendor or partner connection remains trusted after the original purpose has ended, the organisation has created a standing access path that attackers can reuse. The practitioner takeaway is to treat third-party access as revocable identity, not permanent convenience.

Identity blast radius is the right named concept for this dataset: The statistics consistently point to the same pattern: a small trust failure can expand into a large operational and financial loss because access is broad, long-lived, and slow to contain. That is identity blast radius in practice. The concept matters because it shifts attention from initial compromise alone to how far the compromise can travel before identity controls stop it. Governance teams should measure blast radius, not just login success.

What this signals

Identity controls now define breach resilience: The statistics in this article point to a programme reality that many teams still understate. If stolen credentials are the entry path and slow containment is the amplifier, then IAM and PAM are not administrative layers; they are the controls that determine how far an incident can spread before response catches up.

Third-party access should be treated as revocable identity, not durable trust: Vendor accounts, partner connections, and inherited permissions need expiry and ownership or they become latent breach paths. The same governance standard should apply across human and non-human access where delegated trust exists.

Credential-driven breaches expose an identity blast radius problem: When valid access can persist for months, the effective control boundary is not the login screen but the speed at which access can be found, classified, and removed. That shifts programme priorities toward visibility, offboarding, and rapid containment.


For practitioners

  • Tighten credential lifecycle controls Reduce password reuse, enforce stronger authentication for high-risk access, and revoke exposed credentials immediately when compromise is suspected.
  • Map and shrink standing privilege Inventory privileged accounts, service accounts, and vendor access paths, then remove access that is no longer tied to an active business purpose.
  • Shorten breach detection and containment loops Use identity-focused telemetry to confirm which accounts, tokens, and sessions are active so responders can isolate abused access faster.
  • Rework third-party access governance Track third-party accounts as governed identities with expiry, ownership, and offboarding steps, rather than as permanent exceptions.
  • Use breach statistics for board reporting Report credential-driven incidents, dwell time, and third-party exposure as identity risk indicators so leadership sees where controls are failing.

Key takeaways

  • Identity failures, not perimeter failure alone, continue to drive a large share of modern breaches because stolen credentials still work.
  • The 241-day average detection and containment window gives attackers time to exploit legitimate access paths and expand damage.
  • Reducing breach impact depends on stronger credential governance, faster containment, and tighter third-party access lifecycle controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationStolen credentials and reused passwords are the main access path discussed in the article.
NHI-05 — Overprivileged NHIThe article ties long dwell time to broad access that attackers can exploit once inside.
NHI-03 — Vulnerable Third-Party NHIThe article says roughly 30% of breaches involve third-party vendors and their access paths.
Recommendation — Harden authentication flows so compromised secrets cannot continue to grant trusted access. Reduce the blast radius of each credential by removing unnecessary privileges and connected access paths. Govern third-party identities with expiry, ownership, and offboarding so vendor access does not outlive the relationship.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about whether access rights are scoped and removed in time.
Recommendation — Review entitlements continuously and revoke access that no longer matches business need.
MITRE ATT&CKTA0006;TA0008 — Credential Access; Lateral MovementThe breach statistics describe stolen credentials as the main entry point and a path to broader compromise.
Recommendation — Map credential theft and lateral movement indicators to your detection rules and containment playbooks.

Key terms

  • Credential Stuffing: Credential stuffing is an attack that uses stolen username and password pairs from previous breaches to try logging into other services. It works because many people reuse credentials, and because the login attempt uses valid information, it can look ordinary until the surrounding behavior gives it away.
  • Mean Time To Identify: Mean time to identify is the average time between compromise beginning and the organisation recognising it. It measures how quickly monitoring, logging, and identity telemetry can surface abuse. A long identify window means attackers have more time to operate with legitimate-looking access.
  • Mean time to contain: Mean time to contain is the average time it takes to limit an incident after it is detected or suspected. It is a practical resilience metric because it reflects how quickly teams can reduce attacker reach, protect critical identities, and prevent one compromise from spreading further.
  • Third-Party Identity: An identity issued to a partner, vendor, contractor, or external service that can access internal systems. These identities often sit outside normal employee governance and can become persistent trust paths if they are not reviewed, expired, and revoked on schedule.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org