Identity-Based Attacks: How They Work and Why ITDR Matters

Identity is the new perimeter. See how attackers blend in using stolen credentials, manipulate sessions, and exploit insider access – and why ITDR is key to staying ahead.
Identity theft graphic
Aaron Lancaster

·

March 16, 2026

·

Firewalls, endpoint protection, and monitoring tools are still important, but they’re no longer where most attacks start. These days, attackers often don’t need to “hack” at all. They just log in. They steal passwords. They hijack sessions. They exploit trusted machine identities. And once inside, they blend in.

That shift is exactly why Identity Threat Detection and Response (ITDR) matters, and why organizations need to understand the types of identity‑based attacks they face every day.

How Big Is the Problem?

Identity‑based attacks are now the primary vector attackers exploit. According to research from Microsoft, identity attacks surged by 32% in the first half of 2025, and a 97% of those attacks involved password spray or brute force techniques that exploit weak or reused passwords.

Other industry reporting shows that credential theft, phishing, and identity misuse now fuel a majority of breaches: identity‑driven threats accounted for 59% of all confirmed attack cases in early 2025, with specialized malware and phishing making it easier than ever to compromise accounts.

In short: attackers are targeting identities because it works. Traditional defenses often miss these threats because the login looks legitimate on the surface.

Types of Identity-Based Attacks

Credential Theft: The Gateway Attack

Credential theft is the foundational identity attack. This happens when attackers steal usernames and passwords through phishing, fake login pages, malware that collects saved credentials, or leaked databases published on the dark web.

In 2025, researchers at Cybernews reported an 800% surge in credential theft tied to infostealer malware, exposing billions of username-and-password combinations.

Once the attacker has valid credentials, they don’t need to break in… they simply walk through the front door. It’s like finding a key under the welcome mat: the lock hasn’t been picked, but the door opens all the same.

Password Spraying & Credential Stuffing

Attackers often automate their attacks. They know that people tend to reuse weak passwords. So instead of guessing huge numbers of passwords for a single account, they take two common approaches:

  • Password spraying: Trying a small set of common passwords across many accounts to avoid triggering lockouts.
  • Credential stuffing: Taking verified username/password pairs from breaches and “stuffing” them into other services in bulk.

Both techniques exploit poor password hygiene without needing advanced hacking skills – just automation and patience. According to Verizon’s 2025 Data Breach Investigations Report, credential-based attacks account for nearly 60% of breaches worldwide.

Illustrated identity theft graphic

Service Account Compromise and Privilege Escalation

Attackers often start with a single account, human or service account, and then expand their access. Service accounts are high risk because they typically:

  • Have broad, persistent permissions
  • Are less monitored than employee accounts
  • Can access critical systems and data

Once inside, attackers may:

  • Elevate privileges: gain administrator-level access to perform sensitive actions
  • Move laterally: access other accounts or systems to reach high-value targets
  • Blend in: each action may look normal on its own, making detection difficult

Traditional security tools like passwords or multi-factor authentication (MFA) can’t stop this once attackers have valid credentials. That’s why ITDR focuses on monitoring behavior over time, spotting patterns and anomalies that indicate account misuse.

Man-in-the-Middle or Attacker-in-the-Middle Attacks

Some identity-based attacks involve intercepting communications, rather than directly stealing credentials. These attacks fall into two main generations:

Legacy Man-in-the-Middle (MITM) Attacks or Attacker-in-the-Middle (AitM) Attacks

In a traditional AITM attack, an attacker secretly sits between a user and the system they’re accessing. They can capture login credentials, session tokens, or other sensitive information as it travels over the network.

  • Common scenarios include public Wi-Fi or unsecured network connections
  • Attackers may intercept unencrypted traffic or trick users into connecting to fake services
  • The attacker can impersonate the user or steal their login information

Modern Man-in-the-Middle (MITM) Attacks or Attacker-in-the-Middle (AitM) Attacks

A newer variation is more sophisticated. Instead of just capturing data in transit, the attacker actively manipulates authentication sessions:

  • They may inject themselves into multi-factor authentication (MFA) flows (not break MFA – a common misconception)
  • They can trick users into approving access requests for systems they shouldn’t
  • This allows attackers to bypass protections that normally stop stolen credentials

The key difference: legacy attacks are mostly about eavesdropping, while modern attacks are about actively controlling the session to gain access, even with MFA in place. Both attack types are stealthy because the login or session often looks legitimate to traditional security systems.

Insider Misuse and Misconfiguration: Risk from Within

Not all identity attacks originate outside your organization. Legitimate users, whether intentionally or accidentally, can misuse their access. Risks include:

  • Accessing data outside their role
  • Misusing service accounts or shared credentials
  • Leaving legacy accounts active or over-permissioned

These insider risks grow significantly when identity systems are misconfigured, or when permissions are over-granted. Attackers often exploit these gaps to escalate their access or maintain persistence behind the scenes.

Identity attack

Token and Session Hijacking

Modern cloud and SaaS systems often use tokens, session cookies, or API keys instead of—or alongside—passwords. These digital “keys” tell a system, “This user is authenticated.” Attackers who steal these keys often don’t need passwords or MFA as a result.

ITDR tracks how these tokens are used, looking for unusual patterns:

  • Logins from strange locations or devices
  • Access outside normal business hours
  • Uncommon sequences of actions within applications

By watching behavior, not just access, ITDR detects token misuse before attackers can escalate or move laterally.

Real‑World Example: Okta’s 2022 Support System Compromise

In early 2022, Okta, a major identity and access management provider, suffered a breach that affected hundreds of customers. Attackers gained access to a third-party support engineer’s credentials and used them to access Okta systems. While Okta quickly contained the breach, it illustrated several key lessons about identity-based attacks:

  • Even highly secure platforms can be compromised through trusted credentials.
  • Attackers can move laterally and access multiple accounts once inside.
  • Monitoring user behavior and anomalies is critical – traditional password or MFA protections alone may not detect misuse.

How General Informatics Protects You

General Informatics combines strategic expertise with advanced identity‑focused security solutions, powered by Petra Security, to deliver a practical ITDR capability that helps organizations:

  • See deeper: continuous visibility into identity activity, not just logs, so subtle threats don’t go unnoticed
  • Understand behavior: contextual signals separate normal activity from risky behavior
  • Contain faster: automated workflows limit attacker dwell time and spread
  • Act with clarity: insights translated into steps non‑technical teams can act on

Think of our ITDR service as a fire alarm, fire department, and arson investigation team rolled into one. It doesn’t just tell you there’s a problem. It shows where it started, what it touched, and helps you contain it safely.

Learn more about Identity Threat Detection and Response

The Bottom Line: Identity Is the New Attack Surface

Identity‑based attacks have become the primary vector for cybercriminals because they let attackers bypass perimeter defenses and blend into normal user activity. The common denominator among these types of attacks is that they all exploit trust before other more challenging vulnerabilities in systems – trust in identity, as our systems become more identity-centric.

From credential theft surging globally to identity attacks making up the majority of breaches, the statistics show that traditional defenses alone aren’t enough. Security must evolve to focus on behavior and context, not just checks at login. With identity‑centric monitoring and response in place, your organization can stop attackers before they do damage, not just detect them after.

Today's breaches don’t announce themselves.

Know what behavior is normal so you can act when it’s not.

Name(Required)

Connect With Aaron

Get to Know

Aaron Lancaster

Aaron Lancaster is a security expert with a history of providing superior cybersecurity solutions to clients in numerous industries. With over 16 years of experience in the cybersecurity field, Aaron brings a wealth of knowledge and experience to the table and holds credentials that go beyond most in the industry.

In his current role as General Informatics’ Information Security Officer, Aaron is responsible for leading General Informatics’ Security Consulting Practice. Prior to being acquired by General Informatics, Aaron served as the CEO and Founder of 1 Ping Security. Aaron is a highly sought-after speaker and is often delivering keynotes to national security conferences. He has attained a vast amount of security certifications and holds leadership roles amongst multiple security associations and alliances.

In addition, Aaron is a veteran of the U.S. Army, having served as a scout reconnaissance helicopter pilot and Information Assurance Security Officer. He earned a Graduate Certificate in Pentesting and Ethical Hacking from the SANS Technology Institute and holds a Bachelor of Science degree in Aeronautics from Embry-Riddle Aeronautical University.

Share the Word

Scroll to Top

Name(Required)
Please provide any details that suggests of a possible breach. Do not submit sensitive data.
Name(Required)
Want a "Plus One"?(Required)
Meet Our CEO & President

Don Monistere

Don Monistere is an Entrepreneur, Published Author and Accomplished Executive.

Monistere is the CEO and President of General Informatics. Monistere joined the General Informatics team in 2020 and has been actively growing its reach since. General Informatics is one of the fastest growing IT services providers in the Southeast and is considered the leading IT partner for businesses, schools, government agencies, and for the financial and maritime industry.

Name(Required)
Name(Required)