Back to updates Updates · Updated Jan 2026

5. Credential Theft & Identity Attacks

High

Attackers don't need to "break in" if they can simply log in. Infostealers, credential stuffing, session token theft and the hijacking of Single Sign-On (SSO) often grant broad access with a low chance of detection.

Typical signals

  • Impossible travel, unusual IdP apps, unknown OAuth apps
  • New MFA enrollments, token replay, refresh token abuse
  • Credential reuse across VPN, VDI, admin portals and SaaS

Current-state check

  • Mitigations: phishing-resistant MFA, device binding, CA policies
  • Monitor infostealer exposure (leaked creds) and forced resets
  • Protect the IdP: admin segregation, break-glass accounts, logging
Book a call