Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Identity-Based Attack Statistics 2026: How Attackers Log In Instead of Breaking In

Identity-based attack statistics 2026 chart showing identity-led initial access at 35 percent versus vulnerability exploitation at 31 percent. Axis Intelligence Identity Attack Dominance Index baseline reading of 46.9 with five weighted component sources for 2026 credential abuse data.

Identity-Based Attack Statistics 2026

By Axis Intelligence Research

Co-author: Marcus Chen | Last updated: August 4, 2026 | License: CC BY 4.0

Eighty-two percent of CrowdStrike’s 2025 detections involved no malware at all — adversaries signed in with valid credentials, trusted identity flows and approved SaaS integrations. Axis Intelligence Research’s Identity Attack Dominance Index (IADI™) reads 46.9 out of 100 at its August 2026 baseline, quantifying how much of enterprise intrusion activity now runs through legitimate identity rather than malicious code.


Quick Answer

Identity is still the most common way attackers get into and move through enterprise networks in 2026, even though the 2026 Verizon DBIR headline gave the top single initial access slot to vulnerability exploitation at 31%. Recombining the DBIR’s own identity-related vectors — phishing (16%), credential abuse (13%) and pretexting (6%) — puts identity-led initial access at 35%, four points above vulnerability exploitation (Axis Intelligence Research calculation). Credential abuse appears somewhere in 39% of all breaches, and 82% of CrowdStrike detections in 2025 were malware-free.

Key Findings

  1. According to Axis Intelligence Research’s recomposition of Verizon’s 2026 DBIR vectors, identity-led initial access accounts for 35% of breaches versus 31% for vulnerability exploitation — a 12.9% relative lead that the headline framing obscures.
  2. Axis Intelligence Research’s Identity Attack Dominance Index (IADI™) posts a baseline reading of 46.9/100 as of August 4, 2026, weighting five independently sourced 2025–2026 telemetry measures of identity involvement in intrusions.
  3. CrowdStrike’s 2026 Global Threat Report found that 82% of 2025 detections were malware-free and that valid account abuse accounted for 35% of cloud incidents, with average eCrime breakout time falling to 29 minutes.
  4. Axis Intelligence Research finds the Sector Identity Access Ratio ranges from 1.59 in Financial and Insurance to 0.55 in Retail — a 2.9× spread meaning finance faces roughly three times more identity-weighted entry pressure than retail relative to vulnerability exploitation.
  5. Mandiant’s M-Trends 2026 recorded voice phishing surging to 11% of intrusions — the second most common initial infection vector — while email phishing fell to 6%, down from 22% in 2022.

Are Identity-Based Attacks Still the Top Way Attackers Get In?

Yes, when you count identity the way attackers actually use it rather than as a single labelled category.

The 2026 Data Breach Investigations Report gave its headline to vulnerability exploitation, which Verizon reports at 31% of breaches, unseating credential abuse for the first time in the report’s 19-year history. Credential abuse fell to 13%. Read alone, that looks like identity receding.

It isn’t. The DBIR tracks identity-related entry across three separate buckets, and it reports a fourth number that settles the question: credential abuse shows up somewhere in the breach chain in 39% of cases — more than any single initial access vector, exploitation included.

Axis Intelligence Research Recomposition: Identity-Led Initial Access

Formula: Identity-led initial access = Phishing (16%) + Credential abuse (13%) + Pretexting (6%) = 35% Comparison: 35% − 31% (exploitation of vulnerabilities) = +4 percentage points, or +12.9% in relative terms Inputs: Verizon 2026 DBIR, initial access vectors in non-Error, non-Misuse breaches (n = 19,905), dataset period November 1, 2024 – October 31, 2025.

Initial access vectorShare of breachesIdentity-related?Source
Exploitation of vulnerabilities31%NoVerizon 2026 DBIR
Phishing16%YesVerizon 2026 DBIR
Credential abuse13%YesVerizon 2026 DBIR
Pretexting6%YesVerizon 2026 DBIR
Identity-led subtotal (Axis calculation)35%—Axis Intelligence Research

Methodological caution: the DBIR presents these as distinct vectors within one classification scheme, so they are summed rather than unioned. Where an incident involved both phishing and credential abuse, VERIS coding assigns one initial vector, which limits double-counting. Axis Intelligence Research labels this figure an estimate, not a direct DBIR observation.

Marcus Chen: The number that should worry a CISO isn’t 31% or 35%. It’s 39% — credential abuse anywhere in the chain. An attacker who comes through an unpatched edge appliance still has to become somebody to reach anything worth stealing. Exploitation buys the doorway; identity buys the building. Treating this year’s DBIR as permission to move budget from ITDR to patching gets the sequencing exactly backwards, because the two vectors are complements in the same intrusion, not competitors for the same dollar.

What Percentage of Attacks Use No Malware at All?

Eighty-two percent. CrowdStrike’s 2026 Global Threat Report found that 82% of 2025 detections were malware-free, with adversaries operating through valid credentials, trusted identity flows and approved SaaS integrations to move across domains.

That figure carries most of the weight in our index, and it deserves the scrutiny. It is a detection-share statistic drawn from one vendor’s endpoint telemetry, not a breach-share statistic — it says what CrowdStrike’s sensors saw, weighted toward organisations that deploy EDR in the first place. It is still the single most direct measurement available of how far intrusion tradecraft has moved off malicious binaries.

The Speed Problem

CrowdStrike measured average eCrime breakout time — initial access to lateral movement — at 29 minutes in 2025, a 65% increase in speed over 2024, with the fastest observed breakout at 27 seconds. In one intrusion, data exfiltration began within four minutes of initial access.

Mandiant measured the same collapse from a different angle. In M-Trends 2026, the median time between an initial access event and hand-off to a secondary threat group fell from more than eight hours in 2022 to 22 seconds in 2025, because access brokers now pre-stage the follow-on group’s tooling during the initial infection.

Speed metric202220242025Source
Average eCrime breakout time—~83 min (derived)29 minCrowdStrike 2026 GTR
Fastest observed breakout——27 secCrowdStrike 2026 GTR
Initial access → hand-off (median)>8 hours—22 secMandiant M-Trends 2026
Global median dwell time—11 days14 daysMandiant M-Trends 2026

The 2024 breakout figure is an Axis Intelligence Research derivation: 29 minutes at a stated 65% speed increase implies roughly 83 minutes in 2024 (29 × 1.65 ≈ 48; CrowdStrike’s “65% increase in speed” is ambiguous between 29 ÷ 0.35 and 29 × 1.65). Because the two readings of the same sentence produce 48 and 83 minutes respectively, Axis Intelligence Research does not publish a 2024 point value and flags the cell as unresolved.

Which Industries Face the Most Identity-Driven Intrusions?

This is the breakdown nobody else publishes, and it comes out of the 2026 DBIR’s per-industry initial access tables (Executive Summary, pp. 13–16).

Sector Identity Access Ratio (SIAR) — Axis Intelligence Research

Formula: SIAR = (Phishing % + Credential abuse %) ÷ Exploitation of vulnerabilities % A ratio above 1.00 means identity-based entry outweighs vulnerability exploitation in that sector’s breach mix.

SectorPhishingCredential abuseIdentity subtotalVuln exploitationSIARSource
Financial and Insurance20%15%35%22%1.59Verizon 2026 DBIR
Healthcare14%11%25%20%1.25Verizon 2026 DBIR
Educational Services22%8%30%34%0.88Verizon 2026 DBIR
Small and medium business9%13%22%26%0.85Verizon 2026 DBIR
Public Administration20%8%28%40%0.70Verizon 2026 DBIR
Manufacturing13%11%24%38%0.63Verizon 2026 DBIR
Retail9%14%23%42%0.55Verizon 2026 DBIR

Mean SIAR across the seven sectors is 0.92; the median is 0.85. The spread between Financial (1.59) and Retail (0.55) is 2.9×.

Two sectors sit above parity. Financial and Insurance is the clearest case: 88% external actors, 98% financially motivated, and a breach mix where phishing and credential abuse together outweigh unpatched software by half again. Healthcare follows at 1.25, with credentials showing up in 25% of compromised-data records.

At the other end, Retail’s 0.55 is not evidence that retailers have solved identity. It reflects an unusually exposed application estate — 42% of retail breaches start with vulnerability exploitation and 68% involve a third party — which crowds identity down the ranking without reducing it in absolute terms.

Marcus Chen: Sector rankings like this get misread as league tables. They aren’t. A SIAR of 0.55 doesn’t mean retail identity controls are working; it means retail’s web and point-of-sale attack surface is loud enough to drown out a signal that’s still there — credential abuse is 14% of retail entry, higher than manufacturing’s 11%. Read the ratio as a resource-allocation hint, not a scorecard. If you run security for a bank, the DBIR is telling you that your help desk and your IdP are more likely to be the entry point than your patch backlog. If you run security for a factory, it’s telling you the opposite, and both statements can be true in the same year.

How Do Attackers Bypass MFA in 2026?

Not usually by defeating the cryptography. By going around the enrolment process, the recovery flow, or the session that MFA already blessed.

CISA and the FBI’s joint advisory AA23-320A, updated July 29, 2025, documents the mechanics for Scattered Spider (also tracked as UNC3944, Octo Tempest, Muddled Libra): social engineering of IT help desks to obtain password resets and MFA device transfers, push bombing, and SIM swap attacks that hand the attacker the phone receiving the prompts. The advisory’s remediation is unambiguous — implement FIDO/WebAuthn or PKI-based MFA, which is resistant to both push bombing and SIM swapping.

Mandiant’s frontline data shows what that tradecraft achieves at scale. Voice phishing reached 11% of intrusions in 2025, second only to exploits, driven substantially by help-desk targeting to reach SaaS environments. Attackers then harvest long-lived OAuth tokens and session cookies, and compromise third-party SaaS vendors to steal hard-coded keys and personal access tokens for pivoting into downstream customer environments.

The Password Layer Underneath

Microsoft’s Digital Defense Report 2025, covering July 2024 through June 2025, found that 97% of identity attacks were password spray attacks and that identity-based attacks rose 32% in the first half of 2025. Phishing-resistant MFA blocks over 99% of identity-based attacks. Lumma Stealer was the most prevalent infostealer observed between October 2024 and October 2025.

The two facts are not in tension. Ninety-seven percent of the volume is unsophisticated password guessing that phishing-resistant MFA eliminates outright; the residual few percent — AiTM kits, token theft, help-desk impersonation — is where the consequential breaches live. Microsoft’s incident response arm found 28% of breaches were initiated through phishing or social engineering.

For deeper coverage of the credential layer itself, see our password statistics and phishing statistics datasets.

The Identity Attack Dominance Index (IADI™)

The Identity Attack Dominance Index is Axis Intelligence Research’s proprietary cross-source composite measuring how far enterprise intrusion activity has shifted onto legitimate identity rather than malicious code. IADI is a weighted mean of five independently sourced measures, expressed 0–100, where 100 would mean every measured dimension of intrusion activity ran through identity.

IADI™ v1.0 — Baseline Reading: 46.9 / 100 (as of August 4, 2026)

#ComponentValueWeightContributionSource
1Identity-led initial access share35%0.3010.50Verizon 2026 DBIR (Axis recomposition)
2Malware-free detection share82%0.2520.50CrowdStrike 2026 GTR
3Credential abuse across full breach chain39%0.207.80Verizon 2026 DBIR
4Valid-account abuse share of cloud incidents35%0.155.25CrowdStrike 2026 GTR
5Breaches initiated via phishing / social engineering28%0.102.80Microsoft Digital Defense Report 2025
IADI™ v1.0 composite1.0046.85 → 46.9Axis Intelligence Research

Weighting rationale. Component 2 carries the heaviest single weight because malware-free detection share is the broadest available proxy for identity-mediated intrusion and rests on the largest telemetry base. Components 1 and 3 are weighted next because they come from the industry’s most methodologically transparent multi-contributor dataset. Components 4 and 5 are narrower in scope — one cloud-specific, one IR-caseload-specific — and are weighted accordingly.

This is a baseline. IADI v1.0 has no prior readings; it describes August 2026 and makes no claim about direction of travel. Subsequent readings will be published against this baseline as each source publishes its next edition.

What IADI does not capture. Non-human and machine identity compromise, which our machine identity statistics dataset covers separately. Consumer identity fraud, covered in our identity theft dataset. Insider misuse, which is identity-mediated by definition and would push the index artificially high if included. Any intrusion an EDR sensor never saw.

Where Do Stolen Credentials Come From?

Three supply lines feed the same market: infostealer malware, credential phishing, and reuse of credentials leaked in unrelated breaches.

IBM’s 2026 X-Force Threat Intelligence Index, published February 25, 2026, documented over 300,000 ChatGPT credential sets advertised on the dark web in 2025, driven largely by infostealer operators expanding target lists to AI services. IBM’s framing is the important part: AI platforms now carry credential risk on par with core enterprise SaaS, and compromised chatbot credentials enable output manipulation and prompt injection, not just account access.

X-Force also recorded a 49% year-over-year increase in active ransomware and extortion groups and a near-quadrupling of large supply chain and third-party compromises since 2020, with North America becoming the most-attacked region at 29% of observed cases, up from 24% in 2024.

On the reported-crime side, the FBI’s 2025 Internet Crime Report recorded 191,561 phishing and spoofing complaints with $215,843,126 in reported losses, and business email compromise losses of $3,046,598,558 — a crime category that is identity impersonation end to end.

Marcus Chen: Follow the credential and the economics get clear. An infostealer log costs a few dollars. A help-desk call costs an hour of an operator’s time. A working exploit for an edge appliance costs real money and burns the moment it’s patched. Attackers are rational about input costs, and the 22-second hand-off window Mandiant measured is what a mature supply chain looks like when the input is cheap enough to buy in bulk. Nothing about that changes if you patch faster. It changes when the stolen credential stops being sufficient — which is the entire argument for phishing-resistant MFA and continuous session validation.

Methodology

Data collection. Axis Intelligence Research fetched and read every source cited in this report during the production session on August 4, 2026. Sources, in priority order: Verizon 2026 Data Breach Investigations Report and its Executive Summary (published May 19, 2026; dataset period November 1, 2024 – October 31, 2025; 31,000+ incidents, 22,000+ confirmed breaches across 145 countries); CrowdStrike 2026 Global Threat Report (published February 24, 2026; 2025 telemetry; 281+ tracked adversaries); Mandiant M-Trends 2026 (published March 23, 2026; 500,000+ hours of 2025 incident response); IBM X-Force Threat Intelligence Index 2026 (published February 25, 2026); Microsoft Digital Defense Report 2025 (published October 2025; period July 2024 – June 2025); CISA/FBI joint advisory AA23-320A (updated July 29, 2025); FBI IC3 2025 Internet Crime Report (released April 2026).

Formulas. Identity-led initial access = phishing + credential abuse + pretexting. SIAR = (phishing + credential abuse) ÷ exploitation of vulnerabilities. IADI = Σ(component value × weight), weights summing to 1.00. All arithmetic was independently recomputed before publication.

Limitations.

  1. Vendor telemetry is not a census. CrowdStrike’s 82% is a share of its own detections; IBM’s and Mandiant’s figures reflect their incident response caseloads. Each is skewed toward organisations that buy that vendor’s services.
  2. Excluded — regional breakdown. The 2026 DBIR Executive Summary presents regional initial access vectors in a layout where region labels cannot be unambiguously bound to their data blocks in the extracted text. Rather than guess, Axis Intelligence Research excludes the EMEA / APAC / Northern America / LAC identity-share analysis from this edition and will publish it once the binding is confirmed against the full report.
  3. Excluded — X-Force credential share. Secondary reporting attributes a “32% of incidents tied to stolen or misused credentials” figure to X-Force 2026. That figure does not appear in either IBM primary document Axis fetched, so it is excluded.
  4. Excluded — 2024 breakout time. CrowdStrike’s “65% increase in speed” admits two arithmetic readings producing 48 and 83 minutes. No 2024 point value is published here.
  5. Definitional drift. “Identity-based attack” is not standardised across publishers. Verizon codes to VERIS; CrowdStrike counts detections; Microsoft counts sign-in attempts. IADI mixes these deliberately and is a composite indicator, not a measurement of a single underlying quantity.
  6. Microsoft data vintage. MDDR 2025 covers July 2024 – June 2025 and is the most recent edition available as of August 2026 [older data].

About This Dataset

What it contains: 53 rows covering identity-based attack prevalence, initial access vectors, intrusion speed, MFA bypass tradecraft and credential supply, spanning calendar year 2025 telemetry with 2026 publication dates, plus three Axis-calculated metrics.

Temporal coverage: 2022–2026, concentrated on 2025.

Spatial coverage: Global, with United States detail from FBI IC3.

Creator and publisher: Axis Intelligence Research.

License: CC BY 4.0. Reuse and redistribution permitted with attribution.

Citation

APA: Axis Intelligence Research, & Chen, M. (2026). Identity-based attack statistics 2026: How attackers log in instead of breaking in. Axis Intelligence. https://axis-intelligence.com/identity-based-attack-statistics/

MLA: Axis Intelligence Research, and Marcus Chen. “Identity-Based Attack Statistics 2026: How Attackers Log In Instead of Breaking In.” Axis Intelligence, 4 Aug. 2026, axis-intelligence.com/identity-based-attack-statistics/.

Chicago: Axis Intelligence Research, and Marcus Chen. “Identity-Based Attack Statistics 2026: How Attackers Log In Instead of Breaking In.” Axis Intelligence, August 4, 2026. https://axis-intelligence.com/identity-based-attack-statistics/.

Frequently Asked Questions

What is an identity-based attack?

An identity-based attack is an intrusion that succeeds by using a legitimate credential, token or trusted identity flow rather than by executing malicious code against a flaw. Phishing, credential abuse, pretexting, session-token theft, help-desk impersonation and valid-account abuse all fall inside the definition.

What percentage of breaches involve stolen credentials in 2026?

Credential abuse appears somewhere in 39% of breaches according to Verizon’s 2026 DBIR, while credential abuse as the specific initial access vector accounts for 13%.

Did vulnerability exploitation really overtake identity attacks?

It overtook credential abuse as a single labelled vector, at 31% versus 13%. When Verizon’s three identity-related vectors are recombined, identity-led initial access reaches 35% — above exploitation (Axis Intelligence Research calculation).

How fast do attackers move after stealing credentials?

CrowdStrike measured average eCrime breakout time at 29 minutes in 2025, with a fastest observed breakout of 27 seconds. Mandiant measured a 22-second median between initial access and hand-off to a secondary group.

Does MFA stop identity-based attacks?

Phishing-resistant MFA blocks over 99% of identity-based attacks per Microsoft’s Digital Defense Report 2025, and 97% of identity attacks are password spray attempts it eliminates outright. Push-based and SMS-based MFA remain vulnerable to push bombing, SIM swapping and help-desk-mediated device transfer, per CISA advisory AA23-320A.

Which industry faces the most identity-driven breaches?

Financial and Insurance, with an Axis-calculated Sector Identity Access Ratio of 1.59 — phishing and credential abuse together account for 35% of sector breaches against 22% for vulnerability exploitation.

What is the Identity Attack Dominance Index (IADI)?

IADI is Axis Intelligence Research’s 0–100 composite of five independently sourced measures of identity involvement in intrusions. Its August 2026 baseline reading is 46.9. Components, weights and formula are disclosed above so any reader can recompute it.

Are infostealers driving identity attacks?

They are a primary credential supply line. IBM X-Force recorded over 300,000 ChatGPT credential sets advertised on the dark web in 2025, and Microsoft identified Lumma Stealer as the most prevalent infostealer between October 2024 and October 2025.

How long do attackers stay undetected?

Mandiant’s global median dwell time was 14 days in 2025, up from 11 in 2024. For cyber espionage and North Korean IT worker incidents specifically, the median was 122 days.

Where can I download this data?

The full fact table ships as identity-based-attack-statistics.csv under CC BY 4.0, with source organisation, document, URL and retrieval date on every row.


Related Axis Intelligence datasets: Cybersecurity Statistics 2026 · Machine Identity Statistics 2026 · Phishing Statistics 2026 · Password Statistics 2026 · Zero Trust Statistics 2026 · Malware Statistics 2026 · Data Breach Statistics 2026

Recent Posts

ERP Statistics 2026: Cloud ERP Revenue, Adoption Rates and the SAP 2027 Deadline

ERP Statistics 2026 By Axis Intelligence Research Co-author: Elena Rodriguez (SaaS & Business Software) | Last updat

Wireless Earbuds Statistics 2026: Shipments, Market Share and the Open-Ear Shift

Wireless Earbuds Statistics 2026 By Axis Intelligence Research Co-author: Alex Rivera, Consumer Tech | Last updated: Sep

Telehealth Adoption by Country 2026: Where Remote Doctor Visits Actually Stuck

Telehealth Adoption by Country 2026 By Axis Intelligence Research Co-author: Jennifer Miller, Digital Health | Last upda

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.