TL;DR: Verizon's 2026 DBIR shows vulnerability exploitation at 31% of initial access, but identity-related vectors still total 32% when phishing, credential abuse and pretexting are viewed together, according to Push Security's analysis of the report. The real lesson is that identity abuse remains a full-breach-chain problem, not a front-door problem.
Editorial analysis by NHI Mgmt Group, based on content published by Push Security: “What the Verizon DBIR tells us about how breaches happen in 2026”.
Key questions
Q: Where does identity control fail when attackers move beyond initial access?
A: It fails when teams stop measuring identity only at the login event.
Q: Why do vulnerabilities now matter as much as identity controls in breach prevention?
A: Because attackers increasingly start with application weaknesses, then move into identity, privilege, and data access once they are inside.
Q: What are the signs that credential theft is driving a broader breach?
A: Common signs include unusual access to systems beyond the initial entry point, unexpected use of trusted accounts, and activity that looks normal at the authentication layer but abnormal in scope or timing.
Practitioner guidance
- Prioritise breach-chain identity telemetry Track where credentials, sessions, OAuth grants and reused logins appear after first access, not only where they are entered.
- Shorten the lifetime of usable access Review how long tokens, service credentials and third-party permissions remain valid after the original business need has passed.
- Separate social engineering channels by control type Do not treat phishing, pretexting and baiting as one undifferentiated awareness problem.
Bottom line: Verizon's 2026 DBIR does not show identity risk disappearing, it shows identity and vulnerability exploitation running in parallel as competing access paths.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Identity security has not weakened in the DBIR data, it has converged with vulnerability exploitation. The report's apples-to-apples comparison shows identity-related initial access at 32% versus 31% for vulnerability exploitation, which means the market is not moving away from identity risk. It is showing that identity and exploit paths are now equally material in the breach entry mix. For practitioners, that makes identity governance a parallel control plane, not a secondary one.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, ahead of inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do third-party identities change breach accountability?
A: Third-party identities extend accountability beyond internal users because external access often persists through shared apps, OAuth grants, and cloud permissions. The organisation that owns the data must still know who can act, where access lives, and whether offboarding actually removes it. Without that, vendor risk becomes a direct identity risk.
👉 Read our full editorial: Identity attacks still match exploitation in Verizon's 2026 DBIR
Identity security has not weakened in the DBIR data, it has converged with vulnerability exploitation. The report's apples-to-apples comparison shows identity-related initial access at 32% versus 31% for vulnerability exploitation, which means the market is not moving away from identity risk. It is showing that identity and exploit paths are now equally material in the breach entry mix. For practitioners, that makes identity governance a parallel control plane, not a secondary one.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 45% of organisations cite lack of credential rotation as the top cause of NHI-related attacks, ahead of inadequate monitoring and logging at 37% and over-privileged accounts at 37%.
A question worth separating out:
Q: How do third-party identities change breach accountability?
A: Third-party identities extend accountability beyond internal users because external access often persists through shared apps, OAuth grants, and cloud permissions. The organisation that owns the data must still know who can act, where access lives, and whether offboarding actually removes it. Without that, vendor risk becomes a direct identity risk.
👉 Read our full editorial: Identity attacks still match exploitation in Verizon's 2026 DBIR
Identity did not recede in this dataset, it merely lost the headline race. The report shows vulnerability exploitation at 31% of initial access, but identity-related vectors still total 32% once phishing, credential abuse and pretexting are considered together. That means identity remains structurally tied to breach entry, even when another vector edges ahead in the ranking. The practitioner conclusion is simple: do not downgrade identity controls because the top line changed.
A few things that frame the scale:
- The 2026 Verizon DBIR found that exploitation of software vulnerabilities became the leading initial access vector in confirmed breaches, accounting for 31% of incidents.
A question worth separating out:
Q: How should teams handle third-party access that outlives the original need?
A: They should treat it as a governance failure, not a supplier footnote. When MFA is missing, permissions are excessive or access is left in place after a relationship changes, the result is durable exposure. The fix is strict lifecycle control, ongoing attestation and revocation tied to actual business need.
👉 Read our full editorial: Identity attacks still match exploitation in Verizon's 2026 DBIR