Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Credential theft breaches and the identity gaps teams keep missing


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: High-profile incidents at MGM Resorts, TransUnion, McDonald’s, UnitedHealth, and Okta show that password-centric controls still fail under social engineering and visibility gaps, according to Unixi. The real issue is not MFA alone but identity perimeter coverage, unmanaged SaaS, and shared or default credentials that leave attackers room to move.

NHIMG editorial — based on content published by Unixi: How 5 Credential Theft Breaches Could Have Been Prevented

By the numbers:

Questions worth separating out

Q: How should security teams reduce credential theft risk beyond MFA?

A: They should focus on the full identity path, not just the login event.

Q: Why do partial SSO deployments increase breach risk?

A: Partial SSO leaves some applications outside central policy, logging, and offboarding controls.

Q: What do teams get wrong about credential abuse detection?

A: Many teams focus on the moment of theft and miss the later replay activity.

Practitioner guidance

  • Map the real identity perimeter Inventory every authentication path that bypasses central SSO, including legacy portals, vendor tools, and direct SaaS logins.
  • Harden help desk recovery workflows Treat account recovery, reset, and support escalation as privileged actions.
  • Eliminate shared and default credentials Find shared admin passwords, vendor accounts, and legacy defaults across production systems and replace them with individually attributable access.

What's in the full article

Unixi's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • The incident-by-incident breakdown of how each breach chain unfolded across help desk, SSO, and account recovery paths.
  • The control framework for replacing partial SSO with broader identity perimeter coverage across managed and unmanaged applications.
  • The specific handling model for vendor admin accounts, shared credentials, and legacy systems that still resist federation.
  • The practical recommendations for enforcing phishing-resistant, device-bound authentication across the full environment.

👉 Read Unixi's whitepaper on preventing credential theft breaches →

Credential theft breaches and the identity gaps teams keep missing?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

Credential theft is now an identity governance problem, not just an authentication problem. Modern breach patterns show that the weak point is often the control perimeter around recovery, support, and unmanaged access paths. MFA matters, but it cannot compensate for incomplete identity coverage across SaaS, remote access, and vendor-linked accounts. Practitioners should treat credential theft as a lifecycle and governance issue, not a login issue.

A few things that frame the scale:

  • Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to The State of Non-Human Identity Security.
  • Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%.

A question worth separating out:

Q: How do IAM and NHI teams work together on this risk?

A: They should manage human and non-human access as one governance surface. Employee authentication, service accounts, vendor credentials, and application secrets all need ownership, review, and revocation discipline, otherwise attackers will shift to whichever identity type is least visible.

👉 Read our full editorial: Credential theft and partial SSO gaps are exposing modern identity controls



   
ReplyQuote
Share: