TL;DR: Verizon’s 2026 DBIR shows exploitation of vulnerabilities rising to 31% of breaches as the first initial access vector, while credential abuse fell to 13% but still appeared somewhere in 39% of breaches. Descope’s analysis underscores that attackers may be changing entry points, but identity controls, token governance, and partner access remain the real security battleground.
At a glance
What this is: Verizon’s 2026 DBIR says vulnerability exploitation now leads initial access, but credential abuse still dominates the broader breach path and remains a core identity risk.
Why it matters: IAM, PAM, and NHI teams need to treat initial access as only part of the problem, because token abuse, third-party access, and AI-driven identity sprawl still drive real exposure.
By the numbers:
- Exploitation of vulnerabilities reached 31% of breaches as the first known initial access vector, up 55% from 2025’s 20%.
- Credential abuse still appeared at some point in 39% of breaches, more than any other vector.
- Third-party involvement grew to 48% of breaches, a 60% increase year over year.
- The share of employees who are regular AI users on corporate devices tripled in a year, from 15 to 45%.
👉 Read Descope's analysis of Verizon DBIR 2026 identity and breach trends
Context
Credential abuse is no longer the only story in breach entry, but it is still the identity problem that keeps resurfacing deeper in attack chains. The Verizon DBIR data, as discussed by Descope, shows why IAM teams cannot equate a decline in first-step credential abuse with reduced identity risk.
The broader lesson is that access governance now spans customers, partners, service accounts, OAuth tokens, and AI-driven activity. That makes this a practical identity security issue, not just a breach-trend report, because the control failures show up across human IAM, NHI governance, and the emerging agentic identity layer.
Key questions
Q: What breaks when credential abuse is no longer the first step in a breach?
A: Security teams can over-focus on initial access and miss the identity abuse that actually drives persistence and exfiltration. When attackers enter through a vulnerability or pretext, they often still rely on stolen credentials, OAuth tokens, or service accounts to move laterally. The result is a false sense of progress if only login controls improve.
Q: Why do third-party breaches often become identity problems?
A: Third-party breaches become identity problems because attackers usually exploit the trust already extended to a supplier, partner, or managed service. That trust may include federated login, API credentials, or privileged service accounts. Once those identities are abused, the attacker can operate inside normal business workflows instead of breaking through technical barriers.
Q: How can security teams know whether identity controls are actually reducing breach impact?
A: Look for evidence that suspicious accounts are contained fast, active sessions are terminated, and privileged access is limited to the smallest possible set of systems. If a compromised account can still reach sensitive resources after detection, the controls are not working well enough to limit impact.
Q: Who is accountable when a partner’s credentials are used to access your environment?
A: The partner may own the credential, but the relying organisation still owns the access design that allowed it to be useful. That means shared accountability across onboarding, scope definition, monitoring, and offboarding. In regulated environments, the control failure is usually the absence of lifecycle governance, not the existence of a third-party relationship.
Technical breakdown
Why vulnerability exploitation can outrank credential abuse at initial access
Initial access statistics can shift when the measurement model changes, when attackers adapt, or when defenders improve one layer faster than another. In this case, the report added pretexting as a tracked vector, which absorbs some credential abuse activity, but the deeper pattern is that patch backlogs and slow remediation create easier entry than stolen passwords in many environments. That does not mean identity is less important. It means identity abuse often appears later in the intrusion, after the first foothold has been taken through a vulnerability or social pretext.
Practical implication: security teams should treat initial access reporting and identity abuse reporting as separate signals, not as substitutes for one another.
How stolen credentials remain the dominant identity mechanism in breach progression
Credential abuse is often the mechanism that turns a foothold into persistence, lateral movement, or data access. The important distinction in breach analysis is between the first access vector and the later use of tokens, passwords, OAuth grants, or service credentials to move through the environment. That is why credential abuse can fall as an entry point while still remaining the most common technique across the full breach progression. For IAM and NHI programmes, this means the real control surface is not only authentication at sign-in, but credential lifetime, scope, revocation, and monitoring after the first login.
Practical implication: govern credential lifecycle and post-authentication use with the same discipline you apply to sign-in controls.
Why third-party access becomes an identity governance problem
Third-party breaches are rarely just supplier problems. They usually expose a chain of delegated access, weak MFA, excessive privilege, and long-lived tokens that outlive the business relationship or the security assumption that justified them. In practice, OAuth grants, admin accounts, and service accounts become the durable identity layer inside a partner integration, which is why the breach surface extends far beyond the supplier’s environment. This is where human IAM, partner IAM, and NHI governance meet.
Practical implication: treat third-party access as governed identity, with expiry, scoping, and offboarding requirements rather than one-time setup.
Threat narrative
Attacker objective: The attacker’s objective is to convert a single foothold into durable access that can be reused for theft, lateral movement, and broader compromise.
- Entry begins with exploitation of a vulnerability or a pretext that bypasses the normal authentication path and creates a foothold in the target environment.
- Escalation follows when attackers abuse stolen credentials, OAuth tokens, or over-privileged partner access to move from initial access to broader authority.
- Impact occurs when that access is used to exfiltrate data, expand into additional tenants or systems, or enable downstream ransomware and other destructive activity.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Gladinet Hard-Coded Keys RCE Exploitation — Actively exploited hard-coded keys in Gladinet CentreStack and Triofox enable remote code execution.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Credential abuse did not disappear, it moved deeper into the breach chain. The headline drop in first-step credential abuse should not be mistaken for improved identity governance. Attackers still reach for credentials, tokens, and delegated access once they are inside, which means the real control failure sits in post-authentication trust, not only at the login boundary. For IAM and NHI teams, that makes credential lifecycle and privilege scope the decisive control plane.
Third-party access without lifecycle offboarding is now a core breach pattern. The DBIR’s third-party findings reinforce a simple governance failure: access that was granted for a business relationship persists after the security assumption has expired. That is not merely a partner issue, it is an identity governance issue because the entitlement, token, or service account often outlives the review that should have removed it. Practitioner conclusion: offboarding must be part of access design, not an afterthought.
Ephemeral trust debt is the right name for this pattern. Once an organisation grants a token, OAuth scope, or admin entitlement, it accumulates trust debt until expiry, revocation, or rotation closes the window. The problem is not only what the credential can do today, but how long it can continue doing it after the original justification has vanished. The implication for practitioners is to measure the age and blast radius of every delegated identity, not just the count of active accounts.
AI use is expanding the non-human identity problem faster than governance is adapting. Verizon’s shadow AI findings show employees creating unauditable access paths through personal accounts and external AI tools, while bot traffic and agent-like activity continue to rise. That does not automatically make every AI workflow autonomous, but it does mean organisations are creating unmanaged non-human access channels faster than they can classify them. Practitioner conclusion: identity inventories must extend to AI-mediated access before they are overwhelmed by it.
Attackers are optimising for weakest governance, not just weakest passwords. The shift from credential-led entry to vulnerability-led entry does not reduce the value of IAM controls; it shows that attackers use whichever weak point offers the fastest path into a useful identity state. Once inside, they still depend on poor scope control, missing MFA, and static privilege to turn access into impact. The field should read this as a warning that identity risk now starts before authentication and continues well after it.
From our research:
- The share of employees who are regular AI users on corporate devices tripled in a year, from 15 to 45%, according to AI Agents: The New Attack Surface report.
- Another finding in the same report shows that 80% of organisations say their AI agents have already performed actions beyond intended scope, including unauthorised access and data sharing.
- For related governance context, see Top 10 NHI Issues for the identity patterns that matter most across machine and agent access.
What this signals
Ephemeral trust debt: the longer a token, grant, or delegated account remains valid after its original purpose, the more likely it is to become the real breach mechanism rather than the entry point. Teams should watch for environments where access is granted quickly but never meaningfully retired, because that is where identity risk concentrates.
The practical next step is to widen governance beyond human sign-in and into partner credentials, service accounts, and AI-mediated access paths. Verizon’s 45% regular AI-use figure is a reminder that non-human access is expanding faster than most review cycles, so programme owners need inventories that include both delegated and emergent identity states.
For practitioners
- Separate entry-vector reporting from identity-abuse reporting Track vulnerability exploitation, pretexting, credential abuse, and token abuse as distinct metrics so the team does not misread a shift in initial access as a reduction in identity risk.
- Shorten the lifetime of partner and OAuth access Put expiry, revocation, and scope review on every third-party token and delegated grant, especially where access supports customer, tenant, or support workflows.
- Inventory credentials used after first authentication Monitor which passwords, API keys, OAuth grants, and service accounts are still active during lateral movement or data access so post-login abuse becomes visible.
- Extend governance to shadow AI access paths Identify corporate devices and business processes where AI tools are accessed through personal accounts, then require auditable, approved identity paths for those workflows.
- Measure partner privilege by blast radius Review whether each vendor, customer, or integration account can only touch the minimum tenant, dataset, or system needed, and remove standing admin paths where possible.
Key takeaways
- The DBIR does not show identity risk going away, only shifting from first-step compromise to deeper credential and token abuse.
- Third-party and AI-mediated access are now identity governance problems because delegated trust lasts longer than the original security assumption.
- The strongest control response is lifecycle governance for every credentialed path, from partner tokens to service accounts to emerging agent access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | Credential rotation and revocation failures are central to the DBIR's third-party and token abuse patterns. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege access and entitlement governance are central to third-party and service account risk. |
| NIST Zero Trust (SP 800-207) | 5.2 | Zero Trust principles fit the report's emphasis on scoped access and continuous verification. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management applies directly to passwords, tokens, and lifecycle control discussed in the article. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement | The article describes how stolen credentials and token abuse support progression after initial access. |
Map credential abuse to TA0006 and lateral movement to TA0008 when prioritising detections and controls.
Key terms
- Credential Abuse: Credential abuse is the use of valid secrets or accounts by an unauthorised party or for unauthorised purposes. In practice, it often looks like normal authentication unless teams correlate context, privilege, and behaviour. It is one of the most persistent ways identity failures become breaches.
- Delegated Access: Delegated access is permission granted to one identity to act on behalf of another user, service, or system. In NHI environments, this usually appears in OAuth-connected apps and automation tooling. It is powerful, but it must be tightly scoped and reviewed because it can persist long after the original business need ends.
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Token Lifecycle: Token lifecycle is the full sequence of issuing, refreshing, expiring, revoking, and reauthorizing a credential. For delegated access, lifecycle state is the real indicator of whether a connection is still legitimate, because a valid-looking token can still be stale, disconnected, or out of scope.
What's in the full article
Descope's full analysis covers the operational detail this post intentionally leaves for the source:
- The full breakdown of DBIR figures by initial access vector, including the methodology change that affects credential abuse counts.
- The remediation timelines for MFA, password hygiene, and permission misconfiguration across third-party environments.
- The discussion of scoped OAuth tokens, expiry, and revocation as practical controls for partner access.
- The author’s treatment of AI traffic, shadow AI, and what it suggests for future agentic identity governance.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 15, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org