Identity Under Siege: Addressing the 80% Rise in Cyberattacks Targeting Identity Security

3

Identity Under Siege: Why 80% of Cyberattacks Now Target Who You Are — Not What You Own

Compromised credentials have replaced network breaches as the primary entry point for attackers. Experts warn that unchecked identity sprawl is quietly expanding the attack surface for organizations of every size.

The cybersecurity battlefield has shifted dramatically. According to new research from CrowdStrike published September 7, 2026, four out of every five modern cyberattacks are now identity-driven — exploiting compromised credentials rather than breaking through firewalls or network defenses. The implications for businesses are urgent and far-reaching.

Identity has effectively become the new perimeter. Attackers are no longer battering down the front door. They are walking in with a stolen key — and in many organizations, those keys are multiplying faster than anyone can count them.


The Hidden Crisis Inside Your Identity Environment

Andras Fekete, Product Manager for Active Roles at One Identity, argues that the root of this crisis lies not in sophisticated hacking techniques but in organizational blind spots created by rapid growth.

"The explosion of privileged credentials and lack of adequate visibility or oversight can be attributed to growth," Fekete writes, "whether due to migration to the cloud, mergers and acquisitions, the increased use of contractors, or simple organic business growth."

This growth consistently outpaces an organization's ability to govern its identity environment — and that gap is precisely where attackers thrive. Understanding the broader principles behind identity and access management best practices is an essential starting point for any organization looking to close that gap before it becomes a liability.

The Vulnerabilities Accumulating Inside IAM Environments

Fekete identifies several specific vulnerabilities that accumulate inside Identity and Access Management (IAM) environments when left unchecked:

  • Identity sprawl: Rapid organizational growth generates orphaned accounts, duplicate identities, and stale objects. As the number of identities expands, visibility and governance shrink proportionally.
  • Privilege creep: Employees who change roles — joiners, movers, and leavers — frequently accumulate access rights that are never revoked. Over time, these excess privileges create a ready-made pathway for lateral movement by attackers.
  • Shadow admin rights: Nested groups and delegated permissions that no one actively tracks can quietly elevate an account's privileges far beyond what was intended. These hidden administrator rights are nearly invisible yet enormously dangerous.
  • Disconnected systems: Managing separate consoles for each domain or cloud tenant creates identity silos between on-premises and cloud environments. Inconsistent governance policies across these silos generate unchecked privileges and duplicate accounts.
  • Manual JML processes: Joiner-Mover-Leaver workflows that rely on inconsistent manual policies are a persistent source of dormant risk buried inside otherwise functional organizations.

Widely used platforms such as Microsoft Active Directory are frequently at the center of these vulnerabilities — not because the platforms are inherently insecure but because the governance surrounding privileged accounts within them is often inadequate. A closer look at how Microsoft identity and access management works in practice reveals both the strengths organizations can leverage and the governance gaps they need to address.

Why Identity Sprawl Is Harder to Detect Than You Might Expect

One of the most underappreciated aspects of identity sprawl is how gradually and invisibly it develops. A contractor account created for a three-month engagement. A role change that added permissions but never removed the old ones. A nested group that was set up years ago and never reviewed. None of these feel like security incidents at the time — yet each one represents a potential foothold for an attacker with a stolen credential.

The danger is not any single orphaned account. It is the cumulative effect of hundreds of small governance failures across an environment that has never been fully audited. Organizations that have undergone mergers, acquisitions, or rapid cloud migration are particularly exposed, because each transition event tends to generate new identities without a corresponding cleanup of the old ones.


Beyond the Breach: Compliance, Lateral Movement, and What Comes Next

The consequences of a mismanaged identity environment extend well past the initial moment of compromise. Fekete frames the real question not as whether an account will be breached but how far an attacker can travel once inside.

The Lateral Movement Problem

Lateral movement — the ability of an attacker to escalate privileges and access high-value resources after gaining an initial foothold — is what transforms a minor credential compromise into a catastrophic organizational breach. Consider the analogy of someone slipping past a single security guard and then discovering every internal door in the building is unlocked. A single stolen credential, in an environment riddled with privilege creep and shadow admin rights, can quickly become unrestricted access to an organization's most sensitive systems.

This is why visibility matters as much as prevention. Organizations that cannot see the full scope of their identity environment cannot accurately assess how much damage a single compromised account could cause — or how quickly that damage could spread.

Compliance Exposure: The Compounding Risk

Compliance exposure compounds the risk further. Organizations that fail to maintain proper visibility and control over privileged accounts face potential audit failures and regulatory penalties tied to specific data types and reporting requirements. A broad attack surface created by privilege sprawl leaves any organization simultaneously vulnerable to breach and non-compliance — a particularly damaging combination.

Regulators across sectors including finance, healthcare, and critical infrastructure are increasingly focused on identity governance as a core compliance requirement, not a secondary concern. The cost of remediation after a breach is significant. The cost of remediation after a breach and a regulatory finding is considerably higher.


Building a Least-Privilege Framework That Actually Works

The principle of least privilege — ensuring every identity account has exactly the right access at the right time for the right reason and nothing more — is widely recognized as the correct foundation for identity security. The challenge lies in implementation at scale. For organizations working through what this means in practical terms, exploring the evolving landscape of digital identity security and governance provides essential context for how least-privilege frameworks are being applied across modern environments.

Why Automation Is the Critical Differentiator

Fekete is direct about the limits of manual approaches: achieving least privilege through periodic manual reviews and inconsistent processes is largely ineffective in dynamic environments. Automation is the critical differentiator.

Automated Joiner-Mover-Leaver workflows eliminate the manual gaps that create dormant risk. Dynamic groups with policy-based access reduce human error. Continuous entitlement reviews provide the ongoing oversight that point-in-time audits routinely miss. A comprehensive strategy that pairs Identity Governance and Administration with Privileged Access Management addresses privileges holistically — from the outside in.

Centralized Visibility Across Every Environment

Centralized visibility across on-premises, cloud, and hybrid environments is equally essential. Full visibility allows organizations to assess their actual risk exposure, identify anomalies, and prioritize remediation for the highest-risk and highest-privilege accounts first.

Without centralized visibility, governance is reactive at best. Security teams are left responding to incidents rather than identifying and eliminating the conditions that make those incidents possible. In environments where cloud adoption and organizational complexity are both accelerating, a fragmented view of identity is not just a governance inconvenience — it is a structural vulnerability.

For further reference, the National Institute of Standards and Technology (NIST) Identity and Access Management guidance provides a widely respected framework for organizations looking to benchmark their approach against established standards.

Identity Governance as a Continuous Practice

Fekete is clear that achieving this standard is not a one-time project. "It is an evolving strategy with tactics that respond to the landscape and are continuously adapted to fit your needs today," he writes — whether those needs center on general security, specific regulatory compliance, or both.

The foundation of a resilient organization, in his assessment, is a comprehensive least-privilege framework coupled with continuous visibility across the entire identity landscape. Organizations that treat identity governance as a completed task rather than a continuous practice are, in effect, leaving their vulnerabilities available for the next threat actor to discover.

The lesson is straightforward, even if the implementation is not: identity is not a problem you solve once. It is a discipline you maintain — and the organizations that internalize that distinction are the ones best positioned to withstand the identity-driven threats that now define the modern attack landscape.


How You Can Act on This Information

  • Audit your identity environment now. Conduct an immediate review of privileged accounts across Active Directory and cloud environments to identify orphaned accounts, stale objects, and excess permissions before attackers do.
  • Prioritize automation over manual processes. Replace inconsistent JML workflows with automated policy-based systems to close the governance gaps that create the most exploitable risk.
  • Adopt a continuous least-privilege mindset. Treat identity governance as an ongoing operational discipline rather than a compliance checkbox — building regular entitlement reviews and anomaly detection into standard security practice.
You might also like