Join our Newsletter — 33% off our NHI Course

Credential compromise and MFA bypass: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Credential compromise now takes an average of 328 days to identify and contain, while instances rose 300% year over year, according to Abnormal AI. The gap is not just volume but detection failure: teams that rely on MFA and ordinary user-behaviour baselines are still missing account takeovers until long after abuse begins.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Know Your People, Know Your Risk: The Rise of Account Compromise”.

By the numbers:

  • It takes 328 days to identify and contain a breach due to credential compromise.
  • Instances of credential compromise have increased by 300% in the last year.

Key questions

Q: What breaks when account takeover defences rely only on MFA?

A: MFA alone fails when the attacker avoids the strongest sign-in path and pivots to password reset, reused passwords, or automation that makes many attempts cheaply.

Q: Why do credential compromise incidents stay open for so long?

A: They stay open when teams lack enough identity telemetry and triage capacity to investigate suspicious sessions before abuse becomes obvious.

Practitioner guidance

  • Tighten identity anomaly triage Classify unusual login and session behaviour by privilege level, device context, and blast radius so that suspicious access is reviewed before it matures into account takeover.
  • Correlate MFA with session risk Combine MFA events with device reputation, location, token age, and behavioural drift to detect sessions that are authenticated but no longer trustworthy.
  • Reduce blind spots in investigation queues Set explicit escalation criteria for low-frequency anomalies that can indicate credential abuse, especially where the account has access to sensitive systems or data.

Bottom line: Credential compromise becomes far more damaging when organisations rely on MFA as the final trust decision instead of one step in a longer identity control chain.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21390
 

Credential compromise is now a detection problem before it is an authentication problem. The article's 328-day containment figure shows that teams are failing after access is already granted, not just before login succeeds. In IAM terms, this shifts the centre of gravity from sign-in controls to post-authentication monitoring and response. Practitioners should treat identity telemetry as part of the control plane, not a forensic afterthought.

A question worth separating out:

Q: Should organisations prioritise MFA or login anomaly detection first?

A: They should do both, but detection and throttling often need immediate attention when reused passwords are already in circulation. MFA reduces exposure, yet it does not stop password reuse patterns or give early warning when attackers are testing many accounts at once.

👉 Read our full editorial: Credential compromise and MFA bypass are outpacing detection


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.