Attackers Are Increasingly Abusing Digital Identities and Legitimate Accounts

THE BRIEF
CSO Online, citing Eye Security’s State of Incident Response Report 2026, says cybercriminals are increasingly targeting digital identities rather than relying primarily on attempts to break into systems. The report describes attacks on companies as increasingly difficult to detect and says damage can arise within minutes. It identifies identity-based attacks as dominant, with passwords involved in 97% of those incidents. According to the report, misuse of legitimate accounts is a main cause of cloud-security incidents and is helping drive the business of initial-access brokers. CSO Online also says the basic methods used by attackers have not fundamentally changed: compromise still begins with phishing, exploitation of misconfigured or vulnerable internet-facing systems, and social engineering. The supplied excerpt does not provide broader incident totals, victim information, or details about specific organizations. The findings point to a shift in emphasis toward abusing valid access, while familiar entry techniques remain important parts of the attack path.
WHY IT MATTERS
The report’s central warning is that suspicious activity may look like normal access when attackers use legitimate accounts. That makes identity controls, password protection, cloud monitoring, and detection of unusual account behavior important defensive priorities. The findings also connect identity abuse with familiar techniques such as phishing and exploitation of exposed systems, suggesting that organizations should address access security and initial entry methods together rather than treating them as separate problems.
WHO SHOULD CARE
Security leaders, identity and access management teams, cloud administrators, incident responders, and organizations responsible for internet-facing systems should review how legitimate-account misuse and password-related incidents are detected and contained.
WHAT TO DO NOW
- Review privileged and cloud-account activity for unusual access patterns, especially activity involving legitimate credentials.
- Strengthen password protections and assess whether phishing-resistant authentication is available for important accounts.
- Check internet-facing systems for misconfigurations and known vulnerabilities, and prioritize corrective work.
- Exercise response procedures for suspected account compromise, including rapid credential review, access restriction, and investigation of affected sessions.