Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Verizon DBIR 2026: what changed in initial access and identity risk?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15754
Topic starter  

TL;DR: Verizon’s 2026 DBIR shows exploitation of vulnerabilities rising to 31% of breaches as the first initial access vector, while credential abuse fell to 13% but still appeared somewhere in 39% of breaches. Descope’s analysis underscores that attackers may be changing entry points, but identity controls, token governance, and partner access remain the real security battleground.

NHIMG editorial — based on content published by Descope: Verizon DBIR 2026: Credential Abuse Is Down, But Not Out

By the numbers:

Questions worth separating out

Q: What breaks when credential abuse is no longer the first step in a breach?

A: Security teams can over-focus on initial access and miss the identity abuse that actually drives persistence and exfiltration.

Q: Why do third-party breaches often become identity problems?

A: Third-party breaches become identity problems because attackers usually exploit the trust already extended to a supplier, partner, or managed service.

Q: How can security teams know whether identity controls are actually reducing breach impact?

A: Look for evidence that suspicious accounts are contained fast, active sessions are terminated, and privileged access is limited to the smallest possible set of systems.

Practitioner guidance

  • Separate entry-vector reporting from identity-abuse reporting Track vulnerability exploitation, pretexting, credential abuse, and token abuse as distinct metrics so the team does not misread a shift in initial access as a reduction in identity risk.
  • Shorten the lifetime of partner and OAuth access Put expiry, revocation, and scope review on every third-party token and delegated grant, especially where access supports customer, tenant, or support workflows.
  • Inventory credentials used after first authentication Monitor which passwords, API keys, OAuth grants, and service accounts are still active during lateral movement or data access so post-login abuse becomes visible.

What's in the full article

Descope's full analysis covers the operational detail this post intentionally leaves for the source:

  • The full breakdown of DBIR figures by initial access vector, including the methodology change that affects credential abuse counts.
  • The remediation timelines for MFA, password hygiene, and permission misconfiguration across third-party environments.
  • The discussion of scoped OAuth tokens, expiry, and revocation as practical controls for partner access.
  • The author’s treatment of AI traffic, shadow AI, and what it suggests for future agentic identity governance.

👉 Read Descope's analysis of Verizon DBIR 2026 identity and breach trends →

Verizon DBIR 2026: what changed in initial access and identity risk?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15339
 

Credential abuse did not disappear, it moved deeper into the breach chain. The headline drop in first-step credential abuse should not be mistaken for improved identity governance. Attackers still reach for credentials, tokens, and delegated access once they are inside, which means the real control failure sits in post-authentication trust, not only at the login boundary. For IAM and NHI teams, that makes credential lifecycle and privilege scope the decisive control plane.

A few things that frame the scale:

  • The share of employees who are regular AI users on corporate devices tripled in a year, from 15 to 45%, according to AI Agents: The New Attack Surface report.
  • Another finding in the same report shows that 80% of organisations say their AI agents have already performed actions beyond intended scope, including unauthorised access and data sharing.

A question worth separating out:

Q: Who is accountable when a partner’s credentials are used to access your environment?

A: The partner may own the credential, but the relying organisation still owns the access design that allowed it to be useful. That means shared accountability across onboarding, scope definition, monitoring, and offboarding. In regulated environments, the control failure is usually the absence of lifecycle governance, not the existence of a third-party relationship.

👉 Read our full editorial: Verizon DBIR 2026 shows credential abuse is down but not out



   
ReplyQuote
Share: