Identity attack vectors
Nine ways attackers get in through identity. Each one links to the glossary terms that describe how it is done, the threat actors US authorities tie to it, and what the Identity Attack Ledger found in filed breach letters.
Ledger counts below cover 2,161 California breach filings, January 1, 2023 – August 14, 2026.
Phished or stolen credentials
Phished or stolen credentials are a valid username and password that reach an attacker through a fake login page, password reuse, infostealer malware logs, a purchased credential dump or an earlier breach. The attacker then signs in as the real user, so the access looks legitimate and no exploit is needed to get through the front door.
10 terms · 31 cited incidents in the ledger
Social engineering of a person
Social engineering is deceiving a person into granting access on an attacker's behalf. The target might reset a password, enroll a new MFA device, approve a request or read out a code. Phone calls to the help desk, impersonated executives and urgent messages are common forms. The technology works as designed; the human decision is what fails.
4 terms · 12 cited incidents in the ledger
Third-party or contractor access
Third-party access is a way in that belongs to a vendor, contractor or service provider rather than to the organization itself. Remote support tools, shared accounts and partner connections often carry broad permissions and weaker oversight. When the outside party is compromised, the attacker inherits its trusted path into the organizations it serves.
3 terms · 9 cited incidents in the ledger
MFA bypass
MFA bypass is defeating a second factor that is in place, rather than finding an account without one. Attackers flood users with push prompts until one is approved, relay one-time codes through a fake login page, swap a phone number to intercept texts or abuse a weak enrollment or recovery flow.
3 terms · 1 cited incident in the ledger
Session or token theft
Session or token theft is stealing proof that a user already signed in, such as a browser cookie or an access token, and replaying it from another machine. Because the session was created after the password and MFA checks passed, the attacker inherits an authenticated session without needing either factor.
3 terms · not named in any of 2,161 ledger filings
Orphaned or dormant accounts
An orphaned or dormant account is one that outlived the person or purpose it was created for: a former employee, a finished contractor engagement, a retired project or a test login. Nobody watches it and nobody would notice it being used, so a working credential for it gives an attacker quiet, long-lived access.
3 terms · not named in any of 2,161 ledger filings
Over-provisioned standing access
Over-provisioned standing access is permission a user holds beyond what the job needs, all the time, whether or not it is in use. It builds up through role changes, one-off grants nobody revoked and copied access profiles. When that account is compromised, the attacker gets every entitlement it collected, not just the ones the person needs today.
3 terms · not named in any of 2,161 ledger filings
Service-account or non-human identity abuse
Service-account or non-human identity abuse is the use of machine credentials as a way in. API keys, service accounts, OAuth apps, bots and workload tokens often hold broad permissions, usually cannot use interactive MFA and rarely rotate. They also live in code, scripts and configuration files, where an attacker who finds one can sign in as a trusted system.
3 terms · not named in any of 2,161 ledger filings
SSO, IdP, or federation compromise
SSO, IdP or federation compromise is an attack on the identity provider itself rather than on one account. By taking over an administrator, adding a rogue federated domain or stealing a token-signing key, an attacker can mint trusted sign-ins for any user in any connected application. One break at the center can open every door downstream.
3 terms · not named in any of 2,161 ledger filings