Identity-based attacks now drive nearly 90% of security incidents, with 65% of initial access involving credential theft, MFA manipulation, session hijacking, or social engineering. Threat groups like Muddled Libra (Scattered Spider) exemplify the social-first entry pattern, where attackers blend into legitimate administrative behavior after gaining access. SOC leaders are advised to correlate identity signals with endpoint, cloud, SaaS, and network telemetry; consolidate investigations into a unified view; continuously refine detection rules; and dedicate time to proactive threat hunting. Palo Alto Networks Unit 42 promotes its Cortex SecOps platform and Managed XSIAM service as tools for automating correlation and accelerating response.

4m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
The Identity Gap: Why Trust Has Become the New Attack SurfaceAnatomy of a Modern Identity-Driven CompromiseThe Attacker's Playbook in ActionHow Our Unit 42 Managed Services Team RespondsAdvice for SOC Leaders: Look Beyond the LoginWhat's NextThe Unit 42 Managed Services Edge

Questions this post answers

What percentage of security incidents involve identity-based attacks?

Identity weaknesses played a role in nearly 90% of incidents investigated by Unit 42, per the 2026 Unit 42 Global Incident Response Report. Additionally, 65% of initial access activity involved identity-based techniques such as credential theft, MFA manipulation, session hijacking, and social engineering. 87% of incidents also span multiple attack surfaces once an identity is compromised. Security teams tracking identity threat trends find the latest incident data on daily.dev before it reaches the broader industry.

What are the most common initial access techniques used in identity-driven attacks?

The most common initial access techniques in identity-driven attacks are phishing campaigns, social engineering calls, MFA fatigue attacks, compromised third-party accounts, and misuse of help desk processes. Once inside, attackers establish persistence, escalate privileges, and move laterally in ways that closely resemble legitimate administrative behavior, making early detection difficult. SOC teams refining their detection playbooks for identity attacks keep up with evolving attacker techniques on daily.dev.

47 Impressions