TL;DR: Identity-based attacks accounted for 47.7% of all identity incidents that ended in successful account access in Expel’s 2026 Annual Threat Report, which also shows attackers refining familiar endpoint techniques and exploiting low-volume, high-risk cloud activity. The core lesson is that established identity controls such as MFA and conditional access still matter because attackers keep choosing the path of least resistance.
At a glance
What this is: Expel’s annual threat report says identity attacks remained the most frequent and persistent threat in its 2025 incident data, with nearly half of identity incidents resulting in stolen-credential account access.
Why it matters: This matters because IAM and security teams still need to treat credential theft, MFA resistance, and conditional access coverage as operational controls, not theoretical safeguards, across both human and non-human identity estates.
By the numbers:
- 2025, 025, nearly half of all identity incidents, 47.7%, resulted in attackers successfully gaining account access using stolen credentials.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities.
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
👉 Read Expel's 2026 Annual Threat Report on identity, endpoint, and cloud attack trends
Context
Identity compromise remains the most reliable entry path for attackers because it bypasses perimeter controls and lands directly in trusted access paths. In Expel’s 2025 incident data, credential theft and account takeover still dominated the identity problem space, which reinforces how quickly exposed credentials can convert into operational access. For IAM and PAM teams, the issue is not whether identities are protected in principle, but whether controls are enforced consistently across human and machine accounts.
The report also shows a familiar pattern across the wider security stack: attackers refine proven techniques rather than inventing new ones. That means MFA, conditional access, endpoint hardening, and cloud hygiene remain foundational, while NHI governance becomes increasingly important wherever service accounts, tokens, and API credentials can be reused at scale.
Key questions
Q: How should security teams reduce credential stuffing risk across user and machine identities?
A: Use layered controls that limit credential reuse, strengthen authentication, and shorten the time a stolen secret remains useful. For users, that means MFA, passwordless options, and strong monitoring. For non-human identities, it means inventorying secrets, rotating them quickly, and removing standing access wherever possible.
Q: Why do stolen credentials still lead to account takeover in mature environments?
A: Because authentication alone does not prove intent or legitimacy. If attackers can reuse valid credentials, bypass weak recovery flows, or blend into normal session patterns, they can still gain control. Mature environments need contextual detection, not just strong passwords or MFA in isolation.
Q: What do IAM teams get wrong about stronger MFA and conditional access?
A: They often assume a stronger sign-in control will solve identity risk across the environment. In practice, MFA and conditional access protect the front door, but many attacks happen after authentication through legitimate tokens, delegated access, or anomalous application behaviour. That is where governance needs a second control layer.
A: Treat them as one incident chain, not separate problems. Correlate device telemetry, login events, privilege changes, and secret usage so you can revoke access before the attacker completes lateral movement or persistence.
Technical breakdown
Why stolen credentials still dominate identity incidents
Stolen credentials remain effective because they give attackers authenticated access that looks normal to downstream systems. Once a password, token, or session artifact is valid, the attacker does not need to break the control plane again, only to operate within its trust boundaries. MFA and conditional access reduce this risk, but only when they are consistently enforced and paired with anomaly detection, device posture checks, and revocation workflows. In mixed environments, the same logic applies to service accounts and API keys, which often lack the human-layer protections IAM teams assume are already in place.
Practical implication: enforce conditional access and revocation across both human and non-human identities, not just interactive users.
How endpoint refinement keeps old intrusion paths viable
Endpoint attack patterns often succeed because they exploit user habits, software trust, and execution paths that defenders have already normalised. Techniques such as socially engineered execution and backdoored productivity tools work less because they are novel and more because they fit existing operational workflows. The security lesson is that refinement beats novelty when patching, application control, and EDR coverage lag behind attacker adaptation. Where endpoint access leads into identity compromise, the boundary between endpoint security and IAM becomes operationally important.
Practical implication: pair endpoint control validation with identity monitoring so compromised devices cannot become reliable identity launch points.
Cloud infrastructure risk is often hidden by low-volume signals
Cloud threats can appear noisy but low impact until they reveal a broader access or governance gap. Cryptocurrency miners, misused resources, and other low-grade activity often indicate exposed credentials, weak IAM boundaries, or unused privileges that can be escalated later. The main architectural issue is that cloud control failures are frequently identity failures in disguise, especially when API access, instance roles, or secret material are not lifecycle-managed. That makes cloud posture and identity governance inseparable in practice.
Practical implication: investigate low-severity cloud activity as a potential signal of exposed credentials or over-permissioned access.
Threat narrative
Attacker objective: The attacker wants trusted access that blends into normal operations, allowing account takeover, lateral movement, and downstream abuse without noisy exploitation.
- Entry begins when attackers obtain valid credentials or session material through phishing, reuse, or exposure in identity workflows.
- Escalation follows when the attacker uses that access to move into higher-value accounts, cloud resources, or administrative functions that were never meant to be broadly available.
- Impact occurs when the attacker converts trusted access into persistence, data theft, or operational disruption before defenders detect the compromise.
NHI Mgmt Group analysis
Credential theft remains the primary identity control failure, not a side effect. Expel’s data reinforces a pattern we see repeatedly: attackers prefer valid access because it is cheaper, quieter, and more durable than exploitation. That means identity defence has to be built around prevention, detection, and rapid revocation, not around the assumption that access review alone will catch every compromise. For IAM and PAM teams, this is a control design issue, not just a user-awareness issue.
Non-human identities sit inside the same compromise pipeline as human accounts. The article focuses on identity incidents broadly, but the governance lesson extends directly to service accounts, tokens, and API keys because they are equally usable once stolen. This is where OWASP-NHI and NHI lifecycle controls matter: unmanaged machine credentials create the same trust problem as stolen human credentials, often with less visibility. Practitioners should treat machine identity governance as part of the identity incident surface, not a separate discipline.
Established controls still work, but only when coverage is uniform. Expel’s point about MFA and conditional access is important because it cuts through the false idea that attackers have already made them obsolete. The real weakness is partial coverage, exception sprawl, and weak enforcement around non-interactive access paths. That makes the governance question simple: can every identity type be challenged, constrained, and revoked on the same operational timeline?
Cloud and endpoint security problems frequently manifest as identity incidents. The report’s endpoint refinement and cloud risk observations point to a broader structural issue: identity is now the common abuse layer across multiple domains. If device trust, application trust, and cloud access trust are not tied together, defenders see isolated events instead of a chain. The practitioner implication is to align IAM, endpoint, and cloud controls around shared identity telemetry and policy enforcement.
Attackers are optimising for control gaps, which means governance maturity now determines blast radius. When adversaries reuse what works, the differentiator is not novelty in attack tooling but inconsistency in defence. Organisations with strong conditional access, revocation discipline, and privilege boundaries shrink the attacker’s usable window, while fragmented programmes prolong it. The field should read this as a governance maturity test: the more identity estates you have, the more important lifecycle discipline becomes.
What this signals
Identity programmes should expect attackers to keep choosing the easiest authenticated path rather than the loudest exploit path. The practical response is to make credential exposure shorter-lived, detection faster, and revocation automatic across both users and workloads. For teams with machine identity sprawl, credential blast radius: is now a governance metric, not just a technical one.
The most useful planning signal is that endpoint, cloud, and IAM incidents are converging around the same abuse layer. That means security leaders should align identity telemetry with EDR, cloud logs, and access governance so compromise paths can be joined quickly. Where useful, pair this with the NIST Cybersecurity Framework 2.0 and the NIST SP 800-53 Rev 5 Security and Privacy Controls to anchor accountability.
Non-human identity governance will become a stronger differentiator as organisations realise that stolen API keys and service account tokens behave like privileged human credentials once exposed. The teams that can inventory, rotate, and revoke those identities fastest will shrink attacker dwell time first. For practitioners, that makes lifecycle ownership and access review the controls to operationalise now.
For practitioners
- Harden stolen-credential pathways Review every entry point where valid credentials can still grant access without step-up challenge. Prioritise conditional access, MFA enforcement, and rapid session revocation for high-risk accounts, especially where exceptions were created for legacy workflows.
- Map machine credentials into IAM controls Inventory service accounts, API keys, tokens, and certificates alongside human identities so they are subject to lifecycle ownership, usage review, and decommissioning. Use the NHI Lifecycle Management Guide to close orphaned or dormant access.
- Treat endpoint activity as identity evidence Correlate endpoint alerts with identity events so suspicious execution, token theft, or abnormal logins are investigated as one chain. Tie EDR detections to identity telemetry to shorten time to revocation and reduce attacker dwell time.
- Separate low-grade cloud noise from real access risk Do not dismiss miners, odd instance activity, or minor cloud anomalies as purely operational issues. Use them to inspect privilege scope, secret exposure, and unused access paths before attackers repurpose them for more damaging activity.
Key takeaways
- Identity incidents still succeed because valid credentials remain the cleanest path into trusted systems.
- The report’s 47.7% stolen-credential account-access rate shows that established controls fail mainly through inconsistent coverage, not because they no longer work.
- IAM, PAM, endpoint, and NHI governance need to operate as one control system if teams want to shrink attacker dwell time and reduce blast radius.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement; TA0040 , Impact | The report centres on stolen credentials, follow-on movement, and attacker impact. |
| NIST CSF 2.0 | PR.AC-4 | Conditional access and identity enforcement are central to the report’s findings. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential management is directly relevant to the stolen-credential attack pattern. |
| CIS Controls v8 | CIS-5 , Account Management | Account lifecycle and exposure control are core to the report’s identity findings. |
Map identity detections to credential access and lateral movement tactics, then tighten containment around compromised accounts.
Key terms
- Stolen Credentials: Authentication material that an attacker has obtained and can use to impersonate a legitimate user or workload. In practice, this includes passwords, tokens, API keys, and session artifacts that grant trusted access without needing to exploit software vulnerabilities.
- Conditional Access: Conditional access is a policy model that decides whether an action should proceed based on context such as posture, resource sensitivity, timing, and scope. For AI agents, it must be evaluated at request time so a valid credential does not automatically equal permitted behaviour.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Credential Blast Radius: Credential blast radius is the amount of access, data, and system reach that a single compromised secret can unlock. The wider the blast radius, the more damage one leaked token or certificate can cause. Reducing it requires tighter scope, faster revocation, and better segmentation.
What's in the full report
Expel's full report covers the operational detail this post intentionally leaves for the source:
- The incident-handling patterns behind the annual threat data, including how the SOC triaged and resolved alerts across the year.
- The resilience recommendations and defence strategies that Expel says its practitioners use internally and recommend to customers.
- The Field notes sections, where analysts describe what they saw and how they handled specific incidents in more technical detail.
- The MITRE ATT&CK mapping used to connect detections to adversary techniques and response coverage.
👉 The full Expel report adds incident patterns, Field notes, and MITRE ATT&CK mapping for defenders.
Deepen your knowledge
NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps identity and security practitioners build the lifecycle controls required to govern both human and non-human access.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org