Eye Security report says attackers are targeting identities and legitimate access

THE BRIEF
CSO Online reports that Eye Security’s 2026 State of Incident Response Report found cyberattacks increasingly go undetected while damage can occur within minutes. The report says attackers are focusing less on hacking systems and more on exploiting existing access points. Identity-based attacks reportedly dominate the incidents Eye Security tracked, with passwords involved in 97% of cases. Abuse of legitimate accounts is described as a primary cause of cloud security incidents and a driver of the initial access broker business. Eye Security Vice President of Security Operations Lodi Hensen said the underlying methods remain unchanged in 2026: phishing, exploitation of misconfigured or vulnerable internet-enabled systems, social engineering, and software supply-chain attacks. The excerpt also identifies business email compromise as particularly important, but provides no further detail. These findings, as reported, emphasize the connection between identity controls, cloud security, and familiar entry methods rather than a wholly new attack technique.
WHY IT MATTERS
The report links identity abuse to cloud security incidents and initial access broker activity, while finding that passwords appeared in 97% of incidents tracked by Eye Security. Its warning is not limited to sophisticated techniques: phishing, social engineering, exposed systems, and software supply-chain attacks reportedly remain key starting points. Because attacks may go undetected while damage develops within minutes, organizations have reason to examine how legitimate accounts, passwords, and internet-enabled systems are monitored and protected.
WHO SHOULD CARE
Security leaders, cloud administrators, identity and access teams, fraud professionals, and organizations responsible for internet-facing systems or software supply chains should review these reported patterns.
WHAT TO DO NOW
- Review where passwords and legitimate accounts provide access to cloud environments and other critical systems.
- Check internet-enabled systems for misconfigurations and vulnerabilities that could provide an access point.
- Reinforce awareness and controls for phishing, social engineering, and business email compromise.
- Assess software supply-chain exposure and monitor for unusual use of legitimate accounts.
VERIFICATION NOTE
Reported by CSO Online; this archive brief does not add independent confirmation beyond the cited source.