Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On

Blockchain As A Force For Good: Driving Social Impact

August 26, 2026

The Houston Rockets’ Shrewd Negotiating Could Extend Their Title Window

August 26, 2026

How Identity Attackers Read Organizations, Not Defenses

August 26, 2026

Spotify Ad-Skipping Feature: Game Changer Or Game Over

August 26, 2026

Palantir CEO Alex Karp says AI sovereignty is the future

August 26, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » How Identity Attackers Read Organizations, Not Defenses

How Identity Attackers Read Organizations, Not Defenses

By News RoomAugust 26, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
Share
Facebook Twitter LinkedIn Pinterest Email

Santhosh Jayaprakash, Founder and CEO, Unosecur | Building Unified Identity Fabric to provide AI-era identity security.

​In security assessments, the most revealing moment is rarely when you find a misconfiguration. It’s when you find a credential that nobody remembers provisioning.

At Unosecur, we conduct identity risk assessments across organizations that have, by most measures, invested seriously in their security programs: strong perimeter controls, mature endpoint detection and regular audits. What we consistently find underneath is a different kind of exposure: credentials that encode past decisions about trust, for which nobody is accountable anymore. Stale tokens, ownerless service accounts, vendor-held API keys with no expiry. This is evidence of organizational memory running out before the access did.

That gap is what sophisticated identity attackers are looking for before they move.

What Attackers Are Actually Reading

The standard mental model of an identity attack is mechanical: An attacker finds a credential, steals it and uses it. That’s accurate at the technical level but wrong at the strategic level.

According to a Trend Micro report, attackers compromised Context.ai, a small AI productivity tool used by a Vercel employee, in February 2026 by infecting the employee’s device with the Lumma Stealer malware and extracting the employee’s Google Workspace OAuth tokens. Those tokens granted broad access to Vercel’s internal systems. The breach went undetected for approximately two months before Vercel’s own investigation surfaced it. Context.ai didn’t detect the compromise itself.

Instead of attacking Vercel, they attacked what Vercel trusted.

In April 2026, ShinyHunters claimed responsibility for extracting authentication tokens from Anodot, an analytics vendor, and using them to reach Snowflake environments across more than a dozen downstream companies. One compromised analytics vendor led to access to a dozen enterprises. The credential that opened those doors wasn’t one that any of the victim organizations had issued.

This is the strategic layer that most security models miss. Before an attacker acts, they read. In identity environments, what they read is the map of what your organization trusted and forgot to review: third-party OAuth grants with write scope that outlasted their original use case, bot accounts with elevated permissions and no documented owner, credentials that escaped the environments they were issued for and were never recalled.

In 2026, this is the primary attack surface.

Why These Campaigns Stay Invisible

The Vercel breach ran undetected for two months. The Salesloft Drift campaign reached 700 Salesforce customers across 10 days before tokens were revoked. These dwell times result from attackers performing only actions that fall within the compromised credential’s established behavioral profile.

The Salesloft attackers ran bulk Salesforce API exports that matched exactly what Drift’s integration did every day. There was nothing to detect because there was no deviation. The attacker had simply become the credential. Behavioral monitoring is blind to an attacker who has studied what normal looks like and stayed inside it.

This also explains why multifactor authentication (MFA) didn’t stop either campaign. When OAuth tokens are lifted from a vendor’s infrastructure, the authentication event has already occurred. The attack surface is post-authentication. The controls that matter are what the credential is allowed to do after it gets through the login gate.

How The Pattern Has Shifted

What makes the current moment different from five years ago is attacker geometry.

In 2022, attackers used stolen contractor VPN credentials and MFA fatigue to breach Uber, gaining access by targeting the organization with its own credentials. By 2023, attackers targeted identity infrastructure itself, compromising Okta’s support system and using stolen session tokens to hijack customer accounts, including Cloudflare and 1Password.​

By 2024, scale entered the equation. The Snowflake campaign reached approximately 165 organizations from a single credential class: infostealer-harvested logins with no MFA and no rotation, some dating back to 2020. In 2025, attackers exploited vendor integrations through the Salesloft Drift campaign.

By 2026, the vector has moved again to AI tooling and developer productivity software. Context.ai’s compromise gave attackers an OAuth path into Vercel. The blast radius now scales with the vendor’s integration footprint.

The trajectory is consistent: Each year, the entry point moves one step further from the target. The credential that determines your exposure is increasingly becoming the one your vendor issued on your behalf to a system that trusts it unconditionally.

The Unit Of Analysis Has To Change

Most organizations have a reasonable inventory of the credentials they issued. Almost none have a complete map of the trust graph they participate in. Those are two different things, and the gap between them is where these campaigns live.

Every active integration needs one question answered: If this vendor’s environment were compromised tomorrow, what would attackers reach in ours? Most organizations can’t answer that question for their current integrations. The Vercel breach, the Snowflake campaign and the Salesloft incident each measures what that gap costs in dwell time, in downstream victims and in the realization that you rotated everything you knew about and missed everything you had forgotten.

Identity security has always been about knowing who has access to what. In 2026, that question has to include everyone your vendors trusted on your behalf.

Stay aware. Stay secure.​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Santhosh Jayaprakash
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Blockchain As A Force For Good: Driving Social Impact

August 26, 2026

Using Eight Billion AI Personas For Psychology Research Has Its Ups And Downs

August 26, 2026

5 Real-World Vibe Coding Success Stories That Show What AI Can Really Do

August 26, 2026

Hints, Clues And Answer For Wednesday August 26

August 26, 2026

Hints & Clues For Tuesday, August 26 (All In A Day’s Work)

August 25, 2026

A Scorecard For The AI Boom

August 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss

The Houston Rockets’ Shrewd Negotiating Could Extend Their Title Window

News August 26, 2026

While other teams around the NBA were busy making blockbuster moves this offseason, the Houston…

How Identity Attackers Read Organizations, Not Defenses

August 26, 2026

Spotify Ad-Skipping Feature: Game Changer Or Game Over

August 26, 2026

Palantir CEO Alex Karp says AI sovereignty is the future

August 26, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Using Eight Billion AI Personas For Psychology Research Has Its Ups And Downs

August 26, 2026

Capitol Police Arrest California Man After Seizing Guillotine From Truck

August 26, 2026

5 Real-World Vibe Coding Success Stories That Show What AI Can Really Do

August 26, 2026

Trump-Backed Mike Mazzei Narrowly Wins GOP Runoff For Oklahoma Gov. Race

August 26, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.