Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Identity attacks led 2025 incident handling. What should teams do now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Identity-based attacks accounted for 47.7% of all identity incidents that ended in successful account access in Expel’s 2026 Annual Threat Report, which also shows attackers refining familiar endpoint techniques and exploiting low-volume, high-risk cloud activity. The core lesson is that established identity controls such as MFA and conditional access still matter because attackers keep choosing the path of least resistance.

NHIMG editorial — based on content published by Expel: the 2026 Annual Threat Report and its 2025 incident analysis

By the numbers:

Questions worth separating out

Q: How should security teams reduce credential stuffing risk across user and machine identities?

A: Use layered controls that limit credential reuse, strengthen authentication, and shorten the time a stolen secret remains useful.

Q: Why do stolen credentials still lead to account takeover in mature environments?

A: Because authentication alone does not prove intent or legitimacy.

Q: What do IAM teams get wrong about stronger MFA and conditional access?

A: They often assume a stronger sign-in control will solve identity risk across the environment.

Practitioner guidance

  • Harden stolen-credential pathways Review every entry point where valid credentials can still grant access without step-up challenge.
  • Map machine credentials into IAM controls Inventory service accounts, API keys, tokens, and certificates alongside human identities so they are subject to lifecycle ownership, usage review, and decommissioning.
  • Treat endpoint activity as identity evidence Correlate endpoint alerts with identity events so suspicious execution, token theft, or abnormal logins are investigated as one chain.

What's in the full report

Expel's full report covers the operational detail this post intentionally leaves for the source:

  • The incident-handling patterns behind the annual threat data, including how the SOC triaged and resolved alerts across the year.
  • The resilience recommendations and defence strategies that Expel says its practitioners use internally and recommend to customers.
  • The Field notes sections, where analysts describe what they saw and how they handled specific incidents in more technical detail.
  • The MITRE ATT&CK mapping used to connect detections to adversary techniques and response coverage.

👉 Read Expel's 2026 Annual Threat Report on identity, endpoint, and cloud attack trends →

Identity attacks led 2025 incident handling. What should teams do now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Credential theft remains the primary identity control failure, not a side effect. Expel’s data reinforces a pattern we see repeatedly: attackers prefer valid access because it is cheaper, quieter, and more durable than exploitation. That means identity defence has to be built around prevention, detection, and rapid revocation, not around the assumption that access review alone will catch every compromise. For IAM and PAM teams, this is a control design issue, not just a user-awareness issue.

A question worth separating out:

Q: How should organisations respond when identity incidents start appearing alongside endpoint or cloud alerts?

A: Treat them as one incident chain, not separate problems. Correlate device telemetry, login events, privilege changes, and secret usage so you can revoke access before the attacker completes lateral movement or persistence.

👉 Read our full editorial: Identity attacks dominated 2025 incidents in Expel’s annual report



   
ReplyQuote
Share: