TL;DR: The first week of October 2025 brought ten major incidents affecting more than 5.5 million people and organisations, with attackers leaning on credential stuffing, social engineering, ransomware, and third-party compromise across aviation, insurance, automotive, gaming, telecoms, and software, according to FireCompass. The pattern is clear: identity assurance, vendor access, and cloud-hybrid monitoring remain the weakest links when attacks move from entry to exfiltration.
At a glance
What this is: FireCompass’s weekly intelligence report argues that early October 2025 saw a broad spike in breaches driven by credential abuse, third-party compromise, and ransomware across multiple sectors.
Why it matters: For IAM, NHI, and PAM teams, the report is a reminder that valid accounts, delegated access, and cloud-era trust paths can fail at scale when lifecycle controls and monitoring lag attacker speed.
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes.
👉 Read FireCompass's weekly cybersecurity intelligence report on the early October 2025 breach wave
Context
The core problem in this report is not any single breach, but the speed with which attackers turn exposed credentials, cloud trust paths, and third-party access into real compromise. In identity terms, the incident set shows how quickly valid access becomes an enterprise-scale exposure problem when authentication, authorisation, and lifecycle controls are not tightly bound together.
For identity practitioners, the important signal is that the attack surface now spans human credentials, delegated vendor access, and machine-facing cloud workflows. That means IAM, NHI governance, and PAM can no longer be managed as separate concerns when the same compromise path can move from social engineering to lateral movement to exfiltration in one campaign.
This is a typical pattern for mature adversaries, not an outlier. The report’s value is that it shows the recurring shape of modern compromise: entry through trust, persistence through valid access, and impact through scale.
Key questions
Q: What breaks when valid accounts are used to move from access to exfiltration?
A: The main failure is that authentication no longer proves legitimacy after the session starts. Once attackers use valid accounts, they can blend into normal activity, reach cloud data, and pivot laterally while appearing authorised. Defenders must assume the compromise is already inside the identity plane, not waiting at the perimeter.
Q: Why does third-party access so often become a breach path in regulated environments?
A: Third-party access becomes risky when organisations trust external identities more than they should and fail to narrow permissions to the smallest practical scope. Contractors and suppliers often need privileged or persistent access, which expands the attack surface. Without continuous review, detection, and revocation, a compromise in one external account can create downstream regulatory, operational, and data-loss impact.
Q: How can security teams tell whether valid-account abuse is actually being contained?
A: Look for a short gap between successful authentication and containment, limited lateral movement, and no bulk transfer after anomalous login or API activity. If attackers can stay inside long enough to reach multiple systems, the response process is too slow for the identity threat model.
Q: What is the difference between credential stuffing and credential misuse in a breach response?
A: Credential stuffing is the entry method, where stolen username and password pairs are tested at scale. Credential misuse is what happens after compromise, when the attacker uses that access to reach data, APIs, or administrative tools. The response focus changes from login hardening to session containment and entitlement review.
Technical breakdown
Social engineering still opens the door to valid accounts
The report repeatedly shows attackers using human trust failures to obtain valid credentials before moving into cloud or enterprise environments. In identity terms, this is not a pure malware problem. It is a compromise of authentication trust that gives an adversary a legitimate starting point, often via reset flows, stolen credentials, or third-party entry paths. Once valid access exists, traditional perimeter assumptions weaken quickly because the session looks authorised even when the actor is not. The cloud-hybrid model makes this more dangerous because identity becomes the control plane for both data access and administrative reach.
Practical implication: tighten credential verification, reset workflows, and step-up controls wherever an account can unlock cloud access or vendor-connected systems.
Third-party cloud access expands the blast radius
Several incidents in the report pivot through SaaS or vendor-managed environments, especially where API access, CRM data stores, or shared processing systems are involved. The technical issue is not simply exposure, but delegation without sufficient containment. When a third party holds meaningful access into customer data, the compromise boundary shifts from the direct enterprise perimeter to the vendor’s identity and permission model. That turns one weak control into a many-to-many exposure path, because a single compromised integration can reveal large downstream datasets or enable bulk extraction without touching the primary enterprise stack.
Practical implication: inventory delegated access paths, define offboarding triggers for vendors, and review API permissions as part of every third-party risk cycle.
Ransomware now pairs encryption with identity-based exfiltration
The ransomware cases in the report follow the modern double-extortion pattern: attackers gain access, move laterally, steal data, and only then trigger encryption. The identity angle matters because credential harvesting and valid account use are what let attackers stay inside long enough to do both. This is why endpoint-only thinking misses the real failure mode. The decisive weakness is often access persistence, not the final malware payload. Where accounts are over-privileged or poorly monitored, ransomware operators can use internal trust to reach file stores, cloud resources, and operational systems before defenders understand the scope.
Practical implication: correlate identity logs with exfiltration and encryption signals, and treat lateral movement through valid accounts as an immediate containment event.
Threat narrative
Attacker objective: The objective is to convert trusted access into large-scale data theft, extortion leverage, or operational disruption before defenders can revoke the access path.
- Entry began with social engineering, credential stuffing, or third-party access abuse that gave attackers a legitimate foothold inside trusted systems.
- Escalation followed through valid account use, API abuse, and lateral movement across cloud and internal environments until higher-value data stores were reachable.
- Impact came from bulk data exfiltration, extortion, or ransomware deployment, often after the attacker had already used trusted access to stay undetected long enough to maximise damage.
Breaches seen in the wild
- Shai Hulud npm malware campaign — Shai Hulud campaign: npm malware exposed secrets on GitHub.
- Reviewdog GitHub Action supply chain attack — reviewdog/action-setup GitHub Action supply chain attack exposed secrets.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity trust breaks fastest where human credentials, delegated vendor access, and cloud workflows intersect. This report shows that attackers do not need to defeat every layer of security when one trusted identity path can unlock data, administration, and persistence. IAM teams, NHI owners, and PAM leads should treat shared trust paths as the primary governance boundary, not as separate operational silos.
Valid accounts remain the attacker’s most efficient control bypass. Once an actor can operate inside the identity plane, detection becomes a timing problem rather than a perimeter problem. That is why credential resets, API abuse, and cloud access anomalies matter more than the final payload when assessing compromise.
Third-party access without lifecycle offboarding is a standing exposure, not a temporary exception. The report’s breach pattern makes clear that vendor access can outlive its business purpose and remain active long enough to be repurposed by attackers. The implication is that offboarding, entitlement review, and access boundary ownership must be continuous, not event-driven.
Standing privilege is the common denominator across human and machine access paths. Whether the actor is a user, a service account, or a vendor integration, persistent access creates time for attackers to escalate and exfiltrate. That makes privilege duration as important as privilege scope in any identity governance programme.
Identity blast radius is now the better metric than isolated account risk. A single compromised credential can touch customer data, administrative consoles, and cloud services when access relationships are loosely governed. Security leaders should measure how far one identity can move, not just whether the account was protected at login.
From our research:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, according to LLMjacking: How Attackers Hijack AI Using Compromised NHIs.
- From our research: 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- From our research: Explore The 52 NHI breaches Report for recurring compromise patterns and root causes across real incidents.
What this signals
Identity trust paths now define the breach perimeter. As credential abuse and third-party compromise continue to dominate incident chains, practitioners need to shift measurement from isolated control checks to path-based exposure analysis. That means reviewing who can reach data, admin functions, and APIs through a single identity event, then linking those paths to continuous monitoring and faster revocation.
Standing privilege turns short compromises into long incidents. When a login, token, or vendor entitlement persists beyond the need for it, attackers gain the time required to move from entry to impact. Programmes that still rely on periodic review will miss the attacker’s real window, which is why lifecycle controls and revocation speed need to be treated as operational metrics rather than audit artefacts.
Identity blast radius is the concept security teams should start using in planning meetings. The relevant question is not whether an account is protected, but how far one compromised identity can move before containment. For teams maturing NHI governance, this is where the control conversation shifts from credential hygiene to privilege topology and delegated access ownership.
For practitioners
- Map the highest-risk trust paths first Identify the accounts, resets, APIs, and vendor links that can reach sensitive data or cloud administration in one hop. Prioritise paths where a single valid login can expose large datasets or privileged functions.
- Review third-party entitlements for offboarding gaps Check whether vendor access is still active after contracts, projects, or integrations change. Remove access that no longer has a live business owner and require explicit re-approval for any reactivation.
- Correlate identity events with exfiltration signals Tie successful authentication, unusual API activity, and bulk transfer events into one detection path so valid accounts are not treated as harmless simply because they authenticated correctly.
- Shorten the lifetime of exposed credentials Treat public exposure of cloud keys, tokens, and service credentials as an immediate containment issue. Revoke and replace them before attackers can test them, especially where external systems or SaaS integrations are involved.
Key takeaways
- The report’s core lesson is that modern breaches increasingly begin with trusted access, not with exotic exploits.
- The scale is material: ten incidents in one week affected more than 5.5 million people and organisations across multiple sectors.
- Containment depends on identity speed, because the attacker window for exposed credentials and delegated access is now measured in minutes.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0001 Initial Access; TA0006 Credential Access; TA0008 Lateral Movement; TA0040 Impact | The report centres on entry, credential abuse, lateral movement, and extortion chains. |
| OWASP Non-Human Identity Top 10 | NHI-03 | The incidents repeatedly involve exposed credentials, over-privilege, and weak lifecycle control. |
| NIST CSF 2.0 | PR.AC-4 | Access permissions and identity governance are central to the breach patterns in the report. |
| NIST SP 800-53 Rev 5 | IA-5 | Credential handling and authenticator management are directly implicated by the exposed-access cases. |
| NIST Zero Trust (SP 800-207) | The incidents show why trust should not be implicit after initial authentication. |
Strengthen identity and access governance so every high-risk path is explicitly authorised and continuously reviewed.
Key terms
- Valid Account Abuse: Valid account abuse occurs when attackers use legitimate credentials or tokens to enter systems and blend in with normal traffic. It is a preferred tactic because it sidesteps many exploit-based controls and inherits existing privilege. In NHI programmes, service accounts and API keys are common abuse paths when scope and rotation are weak.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Third-Party Entitlement: Access granted to a vendor, supplier, or service provider that lets an external party reach internal systems or data. In identity governance, the key issue is not the existence of the entitlement but whether it still has a current owner, purpose, and offboarding path.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
What's in the full article
FireCompass's full weekly intelligence report covers the operational detail this post intentionally leaves for the source:
- Incident-by-incident timelines for each breach, including the order of access, persistence, exfiltration, and disclosure.
- Technical indicators such as MITRE ATT&CK mappings, IOCs, and log artefacts for detecting similar campaigns.
- Remediation notes and response actions specific to each organisation and attack path.
- The full list of incidents beyond the major cases summarised here, including sector and impact details.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on September 3, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org