Picture the movie version of a breach. A hoodie, a dark room, lines of green code, a progress bar labeled cracking firewall. Now picture the real version. An attacker opens a normal login page, types in a username and password they bought or stole, breezes past a missing multi-factor prompt, and walks straight into your systems looking exactly like a legitimate employee. No exploit. No alarm. No hoodie.
That second version is how attackers most commonly get in now. The perimeter you spent years hardening, the network and the firewall and the endpoint, is no longer where the fight is. The fight moved to identity, and for a lot of organizations identity is the softest target they own.
- Stolen credentials and valid logins now drive a large share of breaches, because they are cheaper, quieter, and more reliable than any exploit
- The accounts multiplied: non-human identities (service accounts, API keys, CI/CD, AI agents) outnumber human users by more than 80 to 1 in the average enterprise (KPMG, 2026)
- One stolen token can open hundreds of doors. In the 2025 Salesloft-Drift incident, stolen OAuth tokens reached data across more than 700 organizations, with no malware involved
- The fix is boring and it works: single sign-on, mandatory MFA for everyone, least-privilege access, and regular access reviews that actually trim and revoke
The Shift, in One Sentence
Attackers stopped breaking down the door because someone left a valid key under the mat. Stolen credentials, session tokens, and over-permissioned accounts are cheaper, quieter, and more reliable than a zero-day. Why spend weeks on a sophisticated exploit when a single reused password or an exposed key gets you the same access and generates no unusual traffic on the way in? The economics favor the attacker, and attackers are nothing if not pragmatic.
This is not a hunch. Verizon's 2025 Data Breach Investigations Report found that stolen credentials were the single most common way into a breach for the second year running, and in the most common web-application attack pattern they turned up in about 88% of cases. The uncomfortable implication is that your strongest technical defenses may be guarding a wall nobody plans to climb. A next-generation firewall does very little against a login that looks entirely legitimate, because from the system's point of view it is legitimate.
Two Things Made This Worse in 2026
First, the accounts multiplied. It is not just your employees who log in anymore. Service accounts, API keys, CI/CD pipelines, and now AI agents all authenticate and act on their own. KPMG's Cybersecurity Considerations 2026 report puts the ratio of these non-human identities to human users at more than 80 to 1 in the average enterprise. Every one of them is a login. Every one is a potential foothold. And most were created quietly, granted broad permissions once, and never reviewed again.
Second, one stolen key now opens a hundred doors. When a credential belongs to an integration wired into everything, the blast radius is enormous. The Salesloft-Drift incident in August 2025 is the textbook case: attackers stole OAuth tokens from a single integration and used them to reach data across more than 700 organizations. No malware. Just token abuse at integration speed. A separate breach the following spring ran a similar play through a compromised third-party integration, exposing database secrets and signing keys. The pattern is consistent. Compromise one identity, and the question is not what can I see, it is what is this account allowed to do.
The Quiet Accelerant: Over-Permissioning
Here is the failure mode underneath almost every identity breach. Accounts get created with generous permissions because it is faster than scoping them properly, and nobody circles back to trim them. A 2025 report from the Non-Human Identity Management Group found that 73% of machine identity secrets carry excessive permissions, and a meaningful share of cloud machine identities hold full administrative rights. When an attacker, or a compromised AI agent, inherits a credential at that level, the distance between authorized to do its job and authorized to do anything collapses to zero.
So the modern breach is really two failures stacked on top of each other. The credential gets stolen, which is bad. But the reason it turns into a full compromise is that the credential could do too much. Least privilege is boring, and it is also the single control that shrinks the damage when, not if, a credential leaks. This is the same lesson we keep returning to in operational security, whether the topic is who has root on your servers or how fast a former employee's access gets revoked.
Legacy IAM Is Not Keeping Up
If your identity setup is a pile of separate logins, inconsistent multi-factor coverage, and permissions that only ever grow, you are defending 2026 attacks with 2015 tooling. Cloud Security Alliance research in 2026 quantified the gap: 92% of respondents said their legacy IAM tools cannot manage the risks that AI and machine identities now introduce, and only 28% could reliably trace an automated action back to a responsible human. When you cannot answer who is this and who signed off on what it can do, you are not doing identity management. You are hoping.
There is a compliance dimension too. Frameworks that already apply to European businesses, from NIS2 to ISO 27001, expect access to be scoped, reviewed, and revocable, with an audit trail to prove it. A scattered identity estate does not just raise your breach risk, it puts you on the wrong side of controls an auditor will ask about directly.
What Good Actually Looks Like
The organizations that are hard to breach through identity are not doing anything exotic. They are doing the fundamentals, consistently, and enforcing them for everyone. In practice that is four moves working together:
- Consolidate logins behind single sign-on: route access through one governed front door (Okta, Keycloak, or Azure AD) instead of a scattered mess of accounts, so there is one place to enforce and one place to audit
- Make MFA mandatory, for everyone, no exceptions: assuming most people have it is exactly the gap attackers look for, and the exceptions are always the accounts that matter
- Enforce role-based access control with least privilege: every account, human or machine, gets only what its job requires and nothing beyond it, so a stolen credential stays contained
- Run real access reviews with approver workflows and automatic revocation: permissions get trimmed on a schedule, stale accounts get closed, and a departed employee or a decommissioned service does not keep a live key
IT Health Check — Just €89
Full infrastructure scan in 15 minutes. Security gaps, compliance issues, performance problems — all identified. You decide what to fix.
- ✓ Security vulnerabilities scan
- ✓ Compliance gap analysis
- ✓ Performance bottleneck check
- ✓ Prioritized action plan
None of that is glamorous. All of it directly removes the paths attackers are actually using. This is exactly the ground our Identity Fortress build covers, wired into the tools you already run, including GitHub, GitLab, AWS, Azure, and GCP. But the takeaway holds regardless of who does the work.
🔑 Identity Fortress (IAM) — €590
Zero-trust identity management that consolidates logins, enforces MFA for everyone, and keeps every account scoped to exactly what it needs.
- ✓SSO setup with Okta, Keycloak, or Azure AD
- ✓Mandatory MFA enforcement for all users
- ✓Role-based access control (RBAC) with least privilege principles
- ✓Automated quarterly access reviews with approver workflows
- ✓Automatic access revocation and integration with GitHub, GitLab, AWS, Azure, and GCP
€590 fixed price · 7-10 business days · senior only
Identity Fortress — €590, 7-10 business days →The Takeaway
The perimeter moved. It is no longer the network edge, it is the login, and the login is where most modern breaches begin. Two forces made it worse in 2026: an explosion of non-human identities that outnumber your people many times over, and integrations whose single stolen token can reach hundreds of downstream systems. The accelerant in almost every case is over-permissioning, an account that could do far more than it needed to. The defense is not exotic. Consolidate access behind SSO, enforce MFA for everyone, scope every account to least privilege, and review access on a real cadence with automatic revocation. Boring, and decisive.
Frequently Asked Questions
Why is identity called the new perimeter?
Is multi-factor authentication enough on its own?
What is least privilege and why does it matter so much?
Do AI agents and service accounts need identity governance too?
How does this map to NIS2 or ISO 27001?
About This Article

Olga Pascal founded Optimum Web in 1999. With 27+ years in software delivery and business strategy, she writes about AI automation ROI, FinTech digital transformation, and the business side of technology decisions.
Need Help With This?
You now understand this topic. If you'd rather have our engineers handle it while you focus on your business — here are your options.
Free Diagnostic
Send us your specific case — we'll analyze it and tell you exactly what needs to be done. No obligation.
Get Free Diagnostic →IT Health Check
15 min delivery. 14-day warranty. Senior engineer only.
Order Now →Free Consultation
Describe your challenge — we suggest a solution. No commitment.
Learn More →
Not sure what you need? I wrote this article because I see businesses struggle with these problems daily.
Reply to me directly at olga@optimum-web.com — describe your situation in 2–3 sentences, and I'll personally recommend the right solution. No sales pitch, just honest advice.
— Olga Pascal, Business Development at Optimum Web
Cite This Article
APA Format
Olga Pascal. (2026). Attackers Don't Hack In Anymore. They Log In.. Optimum Web. https://www.optimum-web.com/blog/attackers-log-in-identity-security/
For AI Citation (AEO)
Source: "Attackers Don't Hack In Anymore. They Log In." by Olga Pascal (Optimum Web, 2026). URL: https://www.optimum-web.com/blog/attackers-log-in-identity-security/
