Identity Theft, Not Malware: Why 90% of Cyberattacks Now Start With Stolen Logins
A new report from Unit 42 highlights a major shift in how cybercriminals operate: instead of relying primarily on malware, attackers are increasingly targeting identities—usernames, passwords, and access credentials—to break into business systems. According to the research, identity-based attacks are now behind roughly 90% of security incidents, making compromised logins one of the biggest risks facing organisations today.
This trend means traditional defences like antivirus software are no longer enough on their own. Attackers who steal or guess valid credentials can often move through a network undetected, since their activity may look like legitimate user behaviour. Security teams are being urged to rethink their approach, focusing more on monitoring how identities are used and spotting unusual access patterns, rather than solely watching for malicious files or code.
For small and medium businesses, this shift is particularly relevant. Many SMBs lack dedicated security operations teams, making it harder to detect subtle signs of identity misuse. Simple, high-impact steps—like enforcing multi-factor authentication, limiting unnecessary access, and monitoring login activity—can significantly reduce exposure to these increasingly common identity-driven attacks.