Identity is the New Black

Image credit: ChatGPT - “Identity is the New Black Fashion Show. - Paris, France”

Every attack begins with an identity. Whether it’s a low-privileged user with read-only access or a dormant account with elevated privileges, the origin of every successful breach starts with a valid user identity.

Across all industries, user identities have emerged as the primary attack vector. As organisations continue to focus their attention and defences on network perimeters and CVEs without the appropriate context, adversaries pivot to exploiting the path of least resistance, the human element, leveraging compromised credentials to infiltrate systems with increasing efficacy.

Threat reports from 2023 and 2024 have highlighted the growing number of credential-based attacks, and yet we continue to hear about organisations where patient zero had not changed their password in five years.

Here are two recent examples of credential-based cyber attacks that have targeted Australians.

At the start of April, a wave of superannuation funds was hit with a credential stuffing campaign. Threat actors are attempting to gain access to unsuspecting user accounts using legitimate credentials stolen in previous large-scale data breaches.

The other notable story broke last week with reports of approximately 31,000 Australian banking customer passwords being actively sold and traded on the dark web.

Below is a direct statement from the latest threat report from Mandiant (acquired by Google):

“Stolen credentials overtook email phishing as the second most frequently observed initial 
infection vector in 2024, representing 16% of intrusions, compared to 14% for email phishing.”
- Mandiant M-Trends Report 2025

Ok, but hang on a second. How do credentials get stolen in the first place?

There are a few ways to do this. I won’t go deep into the details here as that’s a topic for another article entirely.

Adversaries use a combination of the following techniques:

Infostealers

Infostealers are stealthy malware designed to extract sensitive information from infected end-user devices silently. Once installed, often via phishing emails or malicious downloads, they harvest credentials, browser cookies, credit card details, and cryptocurrency wallet data.

Notably, infostealers can bypass multi-factor authentication (MFA) by capturing session cookies, allowing attackers to impersonate users without needing their passwords.

Clickjacking (UI Redress Attacks)

Clickjacking involves deceiving users into interacting with hidden or disguised elements (known as iframes) on a vulnerable web page. Attackers overlay transparent iframes containing legitimate login forms onto malicious sites. Unsuspecting users believe they're entering credentials into a trusted site, but the attacker captures their inputs. 

This technique often complements phishing campaigns, where victims are lured via deceptive links or attachments.

Phishing

Phishing - the Benelli M4 of the cyber scene. A classic technique among threat actors. Phishing remains one of the most common methods for credential theft. Attackers craft deceptive emails or messages that mimic legitimate organisations, enticing users to click on malicious links or download harmful attachments. 

These links often lead to fake login pages designed to capture user credentials. With the advent of AI tools, phishing campaigns have become increasingly sophisticated, thereby enhancing their success rates.​

So, it begs the question: how do we stop the onslaught of credential-based cyberattacks from being so successful?

If it were simply a matter of enabling multi-factor authentication (MFA) or changing passwords regularly, I doubt the number of successful attacks would still be trending upward.

Ideas and Proactive Solutions

Advanced security solutions are often cost-prohibitive for small and medium-sized businesses and are well out of reach for most individuals. However, the good news is that you don’t *really* need fancy tools or expensive subscriptions to protect your user accounts.

Here are my top recommendations for securing your sensitive accounts and information:

Enable phishing-resistant MFA (requirement: MUST)

  • Prioritise methods like authenticator apps provided by Microsoft, Google, Ping, among others. Or use a hardware token.

  • If MFA isn’t an option, use unique passphrases consisting of anywhere between 12 and 16 characters. Use special characters and numbers to increase the complexity.

REGULARLY Manage credentials (requirement: MUST)

  • Avoid storing passwords in browsers as they can be targeted by malware (see above about infostealers) to extract stored credentials.

  • Never reuse the same passphrase or password. Use a reliable password manager to store all your passphrases securely. Challenge yourself to try and remember as many as you can! 🙂

  • Regularly review account activity. Monitor your most frequently used and important accounts for unauthorised access and promptly change passwords if suspicious activity is detected. Here’s what I see on one of my primary email accounts:

Someone is keen…

Reduce your attack surface (requirement: SHOULD/MUST)

  • Secure your devices by installing reputable antivirus software and regularly updating your applications and operating systems to patch known vulnerabilities.

  • Block or uninstall applications from untrusted or unknown sources.

Set up proactive monitoring for credential leaks and data breaches (requirement: SHOULD)

  • Use a free (or paid) dark web monitoring service to notify you if your information shows up in a data breach. There’s a free report service provided by Google that you can use to monitor the dark web for your sensitive information proactively. I’m using this, and I particularly like this option because it allows you to monitor multiple email addresses, whereas most other free reports only monitor a single email address.

  • Mozilla Monitor is another option; you can upgrade to a paid service that helps remove your personal information from data brokers and online directories, but this isn’t as widespread a problem as it is in countries like the United States.

I would actually buy that jacket

Conclusion

As identity-based cyberattacks continue to evolve and increase in sophistication and stealth, placing identity protection and heightened vigilance at the core of cybersecurity strategies is not only prudent but also essential.

The future of businesses and tech will be driven by APIs, and to that effect, APIs will consume identities on a much greater scale than they do today, making identity the true skeleton key that enables access to everything we see and do.

If the impact from compromised credentials is destructive today, it will only worsen in the future. However, there are several ways to overcome this.

By prioritising identity awareness and good security practices, organisations and individuals alike can better protect their most important assets, maintaining confidentiality and trust in an increasingly untrustworthy online world.

Previous
Previous

From Conceptual to Actual: Intelligence-led Security Architecture

Next
Next

The Future of Cyber Security: My Thoughts On The 2023-2024 ACSC Annual Cyber Threat Report