Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

More Baby Boomers’ grown kids are asking them for financial help, forcing them to dip into savings

September 16, 2026

Wells Fargo finance chief sees stronger 2026 loan growth, healthy US economy

September 16, 2026

Melania Trump tells kids not to fear AI amid Nvidia investment announcement

September 15, 2026

In-N-Out managers make six figure salaries, company reveals

September 15, 2026

10-year Treasury yield soars, oil surges above $105 as Fed expected to hike interest rates

September 15, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » How Identity Attackers Read Organizations, Not Defenses

How Identity Attackers Read Organizations, Not Defenses

By News RoomAugust 26, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Santhosh Jayaprakash, Founder and CEO, Unosecur | Building Unified Identity Fabric to provide AI-era identity security.

​In security assessments, the most revealing moment is rarely when you find a misconfiguration. It’s when you find a credential that nobody remembers provisioning.

At Unosecur, we conduct identity risk assessments across organizations that have, by most measures, invested seriously in their security programs: strong perimeter controls, mature endpoint detection and regular audits. What we consistently find underneath is a different kind of exposure: credentials that encode past decisions about trust, for which nobody is accountable anymore. Stale tokens, ownerless service accounts, vendor-held API keys with no expiry. This is evidence of organizational memory running out before the access did.

That gap is what sophisticated identity attackers are looking for before they move.

What Attackers Are Actually Reading

The standard mental model of an identity attack is mechanical: An attacker finds a credential, steals it and uses it. That’s accurate at the technical level but wrong at the strategic level.

According to a Trend Micro report, attackers compromised Context.ai, a small AI productivity tool used by a Vercel employee, in February 2026 by infecting the employee’s device with the Lumma Stealer malware and extracting the employee’s Google Workspace OAuth tokens. Those tokens granted broad access to Vercel’s internal systems. The breach went undetected for approximately two months before Vercel’s own investigation surfaced it. Context.ai didn’t detect the compromise itself.

Instead of attacking Vercel, they attacked what Vercel trusted.

In April 2026, ShinyHunters claimed responsibility for extracting authentication tokens from Anodot, an analytics vendor, and using them to reach Snowflake environments across more than a dozen downstream companies. One compromised analytics vendor led to access to a dozen enterprises. The credential that opened those doors wasn’t one that any of the victim organizations had issued.

This is the strategic layer that most security models miss. Before an attacker acts, they read. In identity environments, what they read is the map of what your organization trusted and forgot to review: third-party OAuth grants with write scope that outlasted their original use case, bot accounts with elevated permissions and no documented owner, credentials that escaped the environments they were issued for and were never recalled.

In 2026, this is the primary attack surface.

Why These Campaigns Stay Invisible

The Vercel breach ran undetected for two months. The Salesloft Drift campaign reached 700 Salesforce customers across 10 days before tokens were revoked. These dwell times result from attackers performing only actions that fall within the compromised credential’s established behavioral profile.

The Salesloft attackers ran bulk Salesforce API exports that matched exactly what Drift’s integration did every day. There was nothing to detect because there was no deviation. The attacker had simply become the credential. Behavioral monitoring is blind to an attacker who has studied what normal looks like and stayed inside it.

This also explains why multifactor authentication (MFA) didn’t stop either campaign. When OAuth tokens are lifted from a vendor’s infrastructure, the authentication event has already occurred. The attack surface is post-authentication. The controls that matter are what the credential is allowed to do after it gets through the login gate.

How The Pattern Has Shifted

What makes the current moment different from five years ago is attacker geometry.

In 2022, attackers used stolen contractor VPN credentials and MFA fatigue to breach Uber, gaining access by targeting the organization with its own credentials. By 2023, attackers targeted identity infrastructure itself, compromising Okta’s support system and using stolen session tokens to hijack customer accounts, including Cloudflare and 1Password.​

By 2024, scale entered the equation. The Snowflake campaign reached approximately 165 organizations from a single credential class: infostealer-harvested logins with no MFA and no rotation, some dating back to 2020. In 2025, attackers exploited vendor integrations through the Salesloft Drift campaign.

By 2026, the vector has moved again to AI tooling and developer productivity software. Context.ai’s compromise gave attackers an OAuth path into Vercel. The blast radius now scales with the vendor’s integration footprint.

The trajectory is consistent: Each year, the entry point moves one step further from the target. The credential that determines your exposure is increasingly becoming the one your vendor issued on your behalf to a system that trusts it unconditionally.

The Unit Of Analysis Has To Change

Most organizations have a reasonable inventory of the credentials they issued. Almost none have a complete map of the trust graph they participate in. Those are two different things, and the gap between them is where these campaigns live.

Every active integration needs one question answered: If this vendor’s environment were compromised tomorrow, what would attackers reach in ours? Most organizations can’t answer that question for their current integrations. The Vercel breach, the Snowflake campaign and the Salesloft incident each measures what that gap costs in dwell time, in downstream victims and in the realization that you rotated everything you knew about and missed everything you had forgotten.

Identity security has always been about knowing who has access to what. In 2026, that question has to include everyone your vendors trusted on your behalf.

Stay aware. Stay secure.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Santhosh Jayaprakash
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

What The Return To The Moon Means For Global Business

September 15, 2026

How To Build AI Skills That Scale Into Agents

September 15, 2026

Signs Your Software Is No Longer Delivering Value

September 15, 2026

The A2P 10DLC Rules Most Businesses Are Breaking Without Knowing It

September 15, 2026

What 25 Years Of Platform Shifts Can Teach Leaders About Surviving AI

September 15, 2026

If You Fight Fraud, You Need To Pay Attention To Residential Proxies

September 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

Wells Fargo finance chief sees stronger 2026 loan growth, healthy US economy

Business September 16, 2026

Wells Fargo expects loan growth in 2026 to be better than its previous forecast and signaled healthy…

Melania Trump tells kids not to fear AI amid Nvidia investment announcement

September 15, 2026

In-N-Out managers make six figure salaries, company reveals

September 15, 2026

10-year Treasury yield soars, oil surges above $105 as Fed expected to hike interest rates

September 15, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

1984 track champ preps South LA bakery for 2028 Olympics

September 15, 2026

Meet Anthropic CEO Dario Amodei’s handpicked far-left ‘evaluators’ he thinks will save us from an AI apocalypse

September 15, 2026

Senate fails to advance Clarity Act in blow to crypto industry ahead of 2026 midterms

September 15, 2026

Bakersfield restaurant Uricchio’s closes after 31 years

September 15, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.