TL;DR: More than 80% of breaches now involve identity compromise, with attackers increasingly using account creation, dormant accounts, weak MFA, and machine identities to stay hidden for days or weeks, according to Hydden. The real issue is not login failure, but continuous identity visibility and behavioural detection across human and machine identities.
Editorial analysis by NHI Mgmt Group, based on content published by Hydden: “Are You Under Attack?”.
By the numbers:
- More than 80% of breaches now involve some form of identity compromise.
Key questions
Q: What breaks when identity reviews happen only on a fixed schedule?
A: Fixed-schedule reviews miss access that is created, used and abused between review cycles.
Q: Why do dormant accounts and weak MFA paths increase compromise risk?
A: Dormant accounts often retain valid trust, old permissions or recovery paths that attackers can exploit without raising obvious alarms.
A: Teams should baseline normal invocation patterns across human and non-human identities, then alert when a token is used by an identity or context it has not previously been paired with.
Practitioner guidance
- Implement continuous identity discovery Replace quarterly visibility checks with continuous discovery across human accounts, machine identities, local accounts and cloud admin paths so new or changed identities surface as they happen.
- Correlate identity and vulnerability signals Join CVE exposure data with identity context so a compromised system can be evaluated for account creation, credential abuse, impersonation and privilege changes at the same time.
- Baseline identity behaviour over time Track frequency, time of access, resource usage and factor changes so the team can detect when an identity starts behaving outside its normal operating pattern.
Bottom line: Identity compromise now shows up first as subtle changes in account behaviour, not as obvious login failures.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Continuous identity security is now a detection discipline, not a periodic review exercise. The article shows that attackers are using identity behaviour, not just login events, to remain hidden. That changes the practical meaning of IAM visibility: the control boundary must extend across account creation, factor changes, machine identities and privileged sessions. For practitioners, identity monitoring now belongs in the same operational lane as detection engineering.
A question worth separating out:
Q: What should IAM and PAM teams do when identity ownership is unclear?
A: They should treat ownership ambiguity as a governance issue, not an inventory issue. If no one can explain why an account, token or certificate exists and who is responsible for it, that identity should be reviewed for removal, reassignment or PAM control. Unowned identities are prime places for stealthy attacker activity.
👉 Read our full editorial: Continuous identity security is now the breach detection problem