“Identity weaknesses played a role in nearly 90% of incidents investigated by Unit 42.”
Identity as the new front door: the scale of the problem
According to the 2026 Unit 42 Global Incident Response Report, identity weaknesses were implicated in nearly 90% of incidents Unit 42 investigated, and 65% of initial access activity involved identity-based techniques. Those two figures together underscore a clear shift: many adversaries are prioritizing credential theft, multifactor authentication (MFA) manipulation, session hijacking and social engineering as their primary routes into enterprise environments.
How attackers get in — and how they move out
Unit 42’s investigations show a repeated pattern at initial access and during expansion. Common initial access vectors cited include phishing campaigns, social engineering calls, MFA fatigue attacks, compromised third‑party accounts and misuse of help‑desk processes. Once inside, attackers establish persistence, elevate privileges and move laterally across environments in ways that often mimic legitimate administrative behavior. That resemblance helps malicious activity remain hidden long enough for adversaries to broaden their foothold before defenders detect the full scope.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleFrom single account to multi‑surface incident
An initial compromised identity rarely stays isolated. Unit 42 highlights that 87% of incidents spanned multiple attack surfaces, meaning a single identity compromise can quickly balloon into a multi‑domain investigation. Whether the immediate objective is ransomware deployment, data theft, financial fraud or long‑term persistence, identity compromise frequently forms the foundation for those broader attacker goals.
Signals are there — but only if you connect them
Unit 42 warns that the warning signs of identity abuse often already exist across an organization’s security controls. The challenge is that, without automated correlation, individual signals can appear low priority when assessed in isolation. Those scattered, low‑priority alerts give attackers room to expand their access before security teams recognize the full scope. The report therefore emphasizes that behavioral context — tying identity activity to endpoint, cloud, SaaS and network telemetry — is necessary to distinguish legitimate logins from compromised accounts.
How Unit 42 responds: Cortex SecOps, MDR, threat hunting and Managed XSIAM
Unit 42 describes a layered operational response built on automated correlation and continuous SOC engineering. Analysts use the Cortex SecOps platform to unify security telemetry into a single investigative view, allowing rapid validation of suspicious activity and a clearer understanding of overall scope. A 24/7 Managed Detection and Response (MDR) team continuously investigates suspicious behaviors while proactive threat hunters search for signs of identity compromise that have not yet generated alerts.
Unit 42 cites several capabilities as central to accelerating detection and response: AI‑driven correlation, behavioral context and Unit 42 threat intelligence. Organizations using Managed XSIAM extend this approach with AI‑driven correlation, integrated investigation and response workflows, plus continuous SOC engineering from Unit 42 experts. Those experts refine the platform’s data integrations, custom detections, correlation rules and automated response playbooks to help identify identity‑driven attacks earlier and respond before attackers expand their access.
What this means for security leaders, SOC teams, and procurement
- Security leaders: Prioritize identity context. A successful login is not by itself proof of normal activity; leaders should insist that identity telemetry be correlated with endpoint, cloud, SaaS and network signals to provide the behavioral context needed to spot compromise.
- SOC teams: Reduce manual investigation and protect time for threat hunting. Consolidating telemetry into a unified investigative view reduces analyst pivots between disconnected tools, and dedicated hunting uncovers credential abuse, privilege escalation and hidden persistence before incidents escalate.
- Procurement and operational decision‑makers: Consider platforms and services that offer continuous SOC engineering and AI‑driven correlation. Unit 42 recommends Managed XSIAM and expert‑led MDR as ways to maintain detection parity with evolving identity‑based threats without having internal teams continuously re‑engineer the platform.
Identity is no longer a narrow authentication problem; it is the axis around which many modern intrusions turn. Unit 42’s findings — the near‑90% involvement of identity weaknesses, the 65% share of identity‑based initial access, and the fact that 87% of incidents cross multiple surfaces — point to a practical requirement: defenders must bind identity telemetry to the rest of their security signals and automate the correlations that humans cannot sustain at scale. Unit 42’s next entry will examine why modern attacks increasingly cross security domains and why unified visibility is essential to stop multi‑surface attacks before they reach business impact.




