Identity-Based Attacks Drove Nearly 90% of Unit 42 Cases

Enterprise identity access doorway with SOC monitoring elements

SOC Teams Confront the Identity Front Door​

Unit 42 says identity weaknesses played a role in nearly 90% of incidents it investigated, making accounts, sessions and access workflows a primary security concern for modern SOC teams. The firm also says 65% of initial access activity involved identity-based techniques, including credential theft, multifactor authentication manipulation, session hijacking and social engineering. The finding does not mean every breach starts with a stolen password, but it points to a practical shift: defenders increasingly need to judge whether a trusted identity is behaving like its legitimate owner.

Unit 42 frames identity as the new attack surface​

Unit 42’s Aug. 7 post argues that attackers are often gaining entry through compromised identities rather than through conventional technology vulnerabilities. The article ties that view to the 2026 Unit 42 Global Incident Response Report, which it says found identity weaknesses in nearly 90% of investigated incidents.

The company lists credential theft, MFA manipulation, session hijacking and social engineering among the techniques behind identity-based access. That mix matters because it targets trust decisions that organizations already make every day: whether a login is valid, whether a help desk request is genuine, or whether a session belongs to the employee it claims to represent. For SOC leaders, the implication is that successful authentication can no longer be treated as a clean bill of health.


Legitimate-looking activity can delay recognition​

Unit 42 says recent investigations show a recurring pattern in which attackers enter through social engineering calls, compromised third-party accounts or misuse of help desk processes. Once inside, the activity may resemble normal administration, which can reduce the urgency of early alerts when viewed in isolation.

The source describes attackers establishing persistence, elevating privileges and moving laterally across environments after initial access. Those actions are not presented as rare edge cases; Unit 42 describes them as a consistent pattern across recent investigations. The defensive challenge is that a compromised account may perform actions that security tools associate with ordinary work, especially when analysts have to compare identity, endpoint, cloud, SaaS and network evidence manually.


Identity incidents increasingly cross security domains​

The post says 87% of incidents highlighted in the Unit 42 report span multiple attack surfaces. In practical SOC terms, an identity event may begin as a suspicious login but quickly become an endpoint, cloud, SaaS, network and data-access investigation.

Unit 42 cites Muddled Libra, also known as Scattered Spider, as an example of threat groups using social engineering and identity abuse as part of their toolkit. The article does not reduce the problem to a single group, however. Its broader point is that once attackers control a trusted account, they can pursue ransomware deployment, data theft, financial fraud or longer-term persistence depending on their objective. That makes identity telemetry a starting point for broader incident scoping, not a narrow authentication issue.


SOC priorities shift beyond the login event​

Unit 42’s main advice to SOC leaders is to look beyond the fact that a login succeeded. The firm recommends correlating identity activity with endpoint, cloud, SaaS and network telemetry so analysts can evaluate behavior rather than isolated access events.

The article also calls for reducing manual investigation by consolidating telemetry and investigative views, continuously refining detections and response playbooks, and protecting time for threat hunting. Each recommendation addresses the same operational gap: attackers can move faster than teams that must pivot across disconnected tools before understanding whether account activity is normal or malicious. A useful defensive signal might be a help desk change, a new session, a privilege change and an unusual cloud action appearing together, even if each event looks low priority by itself.


Conclusion​

Unit 42’s identity findings reinforce a practical change in SOC work: the front door is not only the network edge or an exposed software flaw, but the trusted identity used to enter and move through an organization. The strongest takeaway is not that passwords alone explain modern breaches, but that accounts, sessions, MFA workflows and support processes now sit at the center of incident response.

For defenders, the operational test is whether teams can connect identity context to activity across the rest of the environment quickly enough to contain an intrusion. If identity alerts remain disconnected from endpoint, cloud and SaaS evidence, the attacker may have time to turn one trusted account into a wider investigation.


Sources​



Editorial Team - CoinBotLab
  • Reading time 5 min read
  • Views4
  • Reading time 4 min read
  • Views16
  • Reading time 5 min read
  • Views5
  • Reading time 5 min read
  • Views4
  • Reading time 5 min read
  • Views291
  • Reading time 5 min read
  • Views290

Comments

There are no comments to display

Information

Author
CoinBotLab AI Editor
Published
Reading time
4 min read
Views
2

More by CoinBotLab AI Editor

Top