
Credential theft remains one of the most reliable ways for attackers to access systems. Instead of breaking in, they log in using stolen usernames, passwords, session cookies, or tokens. Once inside, they can impersonate employees, administrators, or even automated service accounts.
This problem is amplified by familiar weaknesses: password reuse, weak credentials, and reliance on single-factor authentication.
Identity Is Now the Front Line
Over the past few years, attacks have shifted away from traditional exploits toward identity-based access.
- Verizon’s 2025 DBIR identifies credential abuse as the most common initial access vector (22%)
- Mandiant reports a rise in infostealer malware, designed specifically to harvest credentials from infected devices
- Microsoft observes attackers adapting as MFA becomes more widespread, moving toward token and session hijacking instead of password guessing
A clear pattern has emerged: as organisations strengthen passwords and deploy MFA, attackers evolve to steal authenticated sessions instead.
How Attacks Actually Happen
Credential theft is rarely a single event. It usually starts with one of a few common entry points:
- Phishing emails that trick users into entering credentials
- Infostealer malware on personal or unmanaged devices
- Credential stuffing using previously leaked passwords
- Legacy protocols and service accounts with weak or no protections
Once attackers have valid credentials, they often avoid detection by behaving like normal users.
What It Looks Like in Practice
Recent incidents highlight how scalable and damaging credential theft has become.
Mandiant documented activity from UNC5537, where attackers used credentials stolen by infostealer malware to access Snowflake customer environments. This enabled large-scale data exfiltration and extortion without exploiting software vulnerabilities.
Snowflake has since advised customers to move away from password-only authentication entirely, reflecting a broader industry shift.
The Business Impact
Credential-based attacks are not just common — they are costly and persistent.
- IBM research shows identity-driven breaches, including phishing, contribute significantly to total breach costs
- Verizon reports that leaked secrets can take a median of 94 days to remediate, particularly when exposed in public repositories
Because these attacks rely on valid access, they often remain undetected longer than traditional intrusions.
Signals You Shouldn’t Ignore
Credential misuse often leaves subtle but detectable traces:
- Repeated failed login attempts followed by a success
- Logins from unusual locations or unfamiliar devices
- “Impossible travel” patterns (e.g. Sydney to London within minutes)
- New OAuth app approvals or API key creation
- Sessions that bypass normal device or security checks
These are early indicators that access may have been compromised.
What Actually Reduces Risk
Mitigating credential theft is less about a single control and more about removing easy paths for attackers.
1. Eliminate single-factor authentication
Require MFA across all business systems. For high-risk users, adopt phishing-resistant methods such as FIDO2.
2. Enforce strong password practices
Use a password manager to ensure unique, long passwords. Shared vaults improve both security and auditability.
3. Control access from unmanaged devices
Define clear BYOD policies. Restrict or monitor access from devices that are not enrolled in device management.
4. Secure service accounts and secrets
Rotate credentials regularly, store them in secure vaults, and prevent secrets from being committed to code repositories.
5. Apply conditional access policies
Use risk-based authentication, device posture checks, and session controls. Not all MFA provides equal protection.
The Bottom Line
Credential theft works because it exploits trust in identity systems rather than weaknesses in software. As defences improve, attackers are focusing more on stealing access than breaking in.
Reducing risk requires treating identity as a core security boundary, not just a login mechanism.
Request a comprehensive cybersecurity assessment
The Fuse Cybersecurity Assessment will provide you with an in-depth look at your organisation’s current cyber security posture.
We will evaluate your organisation’s ability to detect, contain and respond to threats and review your processes in place for identifying vulnerabilities within your infrastructure.