Firewalls, endpoint protection, and monitoring tools are still important, but they’re no longer where most attacks start. These days, attackers often don’t need to “hack” at all. They just log in. They steal passwords. They hijack sessions. They exploit trusted machine identities. And once inside, they blend in.
That shift is exactly why Identity Threat Detection and Response (ITDR) matters, and why organizations need to understand the types of identity‑based attacks they face every day.
How Big Is the Problem?
Identity‑based attacks are now the primary vector attackers exploit. According to research from Microsoft, identity attacks surged by 32% in the first half of 2025, and a 97% of those attacks involved password spray or brute force techniques that exploit weak or reused passwords.
Other industry reporting shows that credential theft, phishing, and identity misuse now fuel a majority of breaches: identity‑driven threats accounted for 59% of all confirmed attack cases in early 2025, with specialized malware and phishing making it easier than ever to compromise accounts.
In short: attackers are targeting identities because it works. Traditional defenses often miss these threats because the login looks legitimate on the surface.
Types of Identity-Based Attacks
Credential Theft: The Gateway Attack
Credential theft is the foundational identity attack. This happens when attackers steal usernames and passwords through phishing, fake login pages, malware that collects saved credentials, or leaked databases published on the dark web.
In 2025, researchers at Cybernews reported an 800% surge in credential theft tied to infostealer malware, exposing billions of username-and-password combinations.
Once the attacker has valid credentials, they don’t need to break in… they simply walk through the front door. It’s like finding a key under the welcome mat: the lock hasn’t been picked, but the door opens all the same.
Password Spraying & Credential Stuffing
Attackers often automate their attacks. They know that people tend to reuse weak passwords. So instead of guessing huge numbers of passwords for a single account, they take two common approaches:
- Password spraying: Trying a small set of common passwords across many accounts to avoid triggering lockouts.
- Credential stuffing: Taking verified username/password pairs from breaches and “stuffing” them into other services in bulk.
Both techniques exploit poor password hygiene without needing advanced hacking skills – just automation and patience. According to Verizon’s 2025 Data Breach Investigations Report, credential-based attacks account for nearly 60% of breaches worldwide.
Service Account Compromise and Privilege Escalation
Attackers often start with a single account, human or service account, and then expand their access. Service accounts are high risk because they typically:
- Have broad, persistent permissions
- Are less monitored than employee accounts
- Can access critical systems and data
Once inside, attackers may:
- Elevate privileges: gain administrator-level access to perform sensitive actions
- Move laterally: access other accounts or systems to reach high-value targets
- Blend in: each action may look normal on its own, making detection difficult
Traditional security tools like passwords or multi-factor authentication (MFA) can’t stop this once attackers have valid credentials. That’s why ITDR focuses on monitoring behavior over time, spotting patterns and anomalies that indicate account misuse.
Man-in-the-Middle or Attacker-in-the-Middle Attacks
Some identity-based attacks involve intercepting communications, rather than directly stealing credentials. These attacks fall into two main generations:
Legacy Man-in-the-Middle (MITM) Attacks or Attacker-in-the-Middle (AitM) Attacks
In a traditional AITM attack, an attacker secretly sits between a user and the system they’re accessing. They can capture login credentials, session tokens, or other sensitive information as it travels over the network.
- Common scenarios include public Wi-Fi or unsecured network connections
- Attackers may intercept unencrypted traffic or trick users into connecting to fake services
- The attacker can impersonate the user or steal their login information
Modern Man-in-the-Middle (MITM) Attacks or Attacker-in-the-Middle (AitM) Attacks
A newer variation is more sophisticated. Instead of just capturing data in transit, the attacker actively manipulates authentication sessions:
- They may inject themselves into multi-factor authentication (MFA) flows (not break MFA – a common misconception)
- They can trick users into approving access requests for systems they shouldn’t
- This allows attackers to bypass protections that normally stop stolen credentials
The key difference: legacy attacks are mostly about eavesdropping, while modern attacks are about actively controlling the session to gain access, even with MFA in place. Both attack types are stealthy because the login or session often looks legitimate to traditional security systems.
Insider Misuse and Misconfiguration: Risk from Within
Not all identity attacks originate outside your organization. Legitimate users, whether intentionally or accidentally, can misuse their access. Risks include:
- Accessing data outside their role
- Misusing service accounts or shared credentials
- Leaving legacy accounts active or over-permissioned
These insider risks grow significantly when identity systems are misconfigured, or when permissions are over-granted. Attackers often exploit these gaps to escalate their access or maintain persistence behind the scenes.
Token and Session Hijacking
Modern cloud and SaaS systems often use tokens, session cookies, or API keys instead of—or alongside—passwords. These digital “keys” tell a system, “This user is authenticated.” Attackers who steal these keys often don’t need passwords or MFA as a result.
ITDR tracks how these tokens are used, looking for unusual patterns:
- Logins from strange locations or devices
- Access outside normal business hours
- Uncommon sequences of actions within applications
By watching behavior, not just access, ITDR detects token misuse before attackers can escalate or move laterally.
Real‑World Example: Okta’s 2022 Support System Compromise
In early 2022, Okta, a major identity and access management provider, suffered a breach that affected hundreds of customers. Attackers gained access to a third-party support engineer’s credentials and used them to access Okta systems. While Okta quickly contained the breach, it illustrated several key lessons about identity-based attacks:
- Even highly secure platforms can be compromised through trusted credentials.
- Attackers can move laterally and access multiple accounts once inside.
- Monitoring user behavior and anomalies is critical – traditional password or MFA protections alone may not detect misuse.
How General Informatics Protects You
General Informatics combines strategic expertise with advanced identity‑focused security solutions, powered by Petra Security, to deliver a practical ITDR capability that helps organizations:
- See deeper: continuous visibility into identity activity, not just logs, so subtle threats don’t go unnoticed
- Understand behavior: contextual signals separate normal activity from risky behavior
- Contain faster: automated workflows limit attacker dwell time and spread
- Act with clarity: insights translated into steps non‑technical teams can act on
Think of our ITDR service as a fire alarm, fire department, and arson investigation team rolled into one. It doesn’t just tell you there’s a problem. It shows where it started, what it touched, and helps you contain it safely.
Learn more about Identity Threat Detection and Response
The Bottom Line: Identity Is the New Attack Surface
Identity‑based attacks have become the primary vector for cybercriminals because they let attackers bypass perimeter defenses and blend into normal user activity. The common denominator among these types of attacks is that they all exploit trust before other more challenging vulnerabilities in systems – trust in identity, as our systems become more identity-centric.
From credential theft surging globally to identity attacks making up the majority of breaches, the statistics show that traditional defenses alone aren’t enough. Security must evolve to focus on behavior and context, not just checks at login. With identity‑centric monitoring and response in place, your organization can stop attackers before they do damage, not just detect them after.
Today's breaches don’t announce themselves.
Know what behavior is normal so you can act when it’s not.
Connect With Aaron
Get to Know
Aaron Lancaster
Aaron Lancaster is a security expert with a history of providing superior cybersecurity solutions to clients in numerous industries. With over 16 years of experience in the cybersecurity field, Aaron brings a wealth of knowledge and experience to the table and holds credentials that go beyond most in the industry.
In his current role as General Informatics’ Information Security Officer, Aaron is responsible for leading General Informatics’ Security Consulting Practice. Prior to being acquired by General Informatics, Aaron served as the CEO and Founder of 1 Ping Security. Aaron is a highly sought-after speaker and is often delivering keynotes to national security conferences. He has attained a vast amount of security certifications and holds leadership roles amongst multiple security associations and alliances.
In addition, Aaron is a veteran of the U.S. Army, having served as a scout reconnaissance helicopter pilot and Information Assurance Security Officer. He earned a Graduate Certificate in Pentesting and Ethical Hacking from the SANS Technology Institute and holds a Bachelor of Science degree in Aeronautics from Embry-Riddle Aeronautical University.