Join our Newsletter — 33% off our NHI Course

Account takeovers and compromised credentials: are controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Compromised credentials caused 20% of all data breaches in 2021, remained the most common initial attack vector, and took an average of 250 days to detect plus 91 days to contain, according to Abnormal AI. Stolen account access still defeats many defences because detection lags and containment assumes the breach is already visible.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Troy Hunt on ATO: Account Takeovers as the Hidden Threat”.

By the numbers:

  • In 2021, compromised credentials were responsible for 20% of all data breaches.
  • It takes an average of 250 days to realize that the compromise has even occurred.
  • It takes another 91 days to contain the breach after compromise is detected.

Key questions

Q: What breaks when a compromised credential is enough to access business systems?

A: The access model breaks because authentication is being treated as trust rather than proof of legitimacy.

Q: Why do account takeovers still succeed even in organisations with strong MFA adoption?

A: Account takeovers still succeed because attackers target the weak points around MFA rather than the factor itself.

Practitioner guidance

  • Harden high-value account monitoring Prioritise executive mailboxes, finance accounts, and identity administrator accounts for anomaly detection, because a single takeover in these roles creates disproportionate downstream risk.
  • Correlate identity telemetry with session behaviour Link authentication events, device signals, and mailbox activity so suspicious reuse of valid credentials can be detected before the attacker finishes abusing the session.
  • Tighten password reset and recovery workflows Review every process that allows a mailbox or other account to recover access to another account, since attackers often use the first compromise to obtain the second.

Bottom line: Compromised credentials are still a primary path to account takeover because trusted accounts can be abused after authentication succeeds.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Compromised credential defence is failing because authentication success is being mistaken for identity assurance. The article shows that stolen credentials remain the most common initial attack vector, which means the control problem begins after login, not before it. Identity programmes that stop at password policy or MFA deployment are still assuming the credential itself is the boundary. The practical conclusion is that account trust has to be continuously re-evaluated, not granted once at sign-in.

A few things that frame the scale:

  • 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to the Ultimate Guide to NHIs.
  • Compromised credentials take an average of 246 days to identify and contain, according to IBM's 2025 Cost of a Data Breach Report.

A question worth separating out:

Q: How should security teams respond when an email account is taken over?

A: Teams should contain the identity first, then inspect the inbox for rule changes, forwarding abuse, and suspicious sign-ins. If the account can still send trusted mail, the attacker can continue operating even after the original message is removed. Fast containment matters because post-compromise abuse often happens inside normal business workflows.

👉 Read our full editorial: Account takeovers expose the limits of compromised credential defences


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.