Organizations now manage thousands of human and non-human identities across cloud services, software-as-a-service applications, endpoints, and remote environments. As hybrid working, Bring-Your-Own-Device (BYOD), and third-party access continue to expand, security teams are losing visibility over who has access to what and whether that access can be trusted.
Phishing and Credential Abuse
Credential abuse remains one of the most reliable ways for attackers to gain access to an organization, accounting for 22% of breaches in 2025. Attackers obtain usernames and passwords through infostealer malware, phishing campaigns, or credential dumps from previous breaches.
While multi-factor authentication (MFA) is still one of the most important defenses against account compromise, attackers have adapted their tactics to target the authentication process itself. One common technique is MFA fatigue, also known as prompt bombing. This involves repeatedly triggering MFA approval requests until the user eventually accepts one, usually out of frustration at the barrage of notifications they’re receiving.
MFA Fatigue and Adversary-in-the-Middle Frameworks
A well-known example of MFA fatigue came in 2022, when attackers targeted an Uber employee with repeated MFA prompts until one was approved. That initial access allowed the attackers to escalate privileges and move deeper into Uber’s environment, ultimately compromising large parts of its cloud infrastructure and exposing employee data.
Attackers are also using adversary-in-the-middle frameworks and session hijacking tools to bypass MFA entirely by stealing authenticated session tokens after login. Credential phishing attacks are bypassing traditional protections, with the latest attacks reaching new levels of sophistication.
Phishing Attacks and Device Security
Threat researchers at Outpost24, Specops’ parent company, recently uncovered a phishing campaign that employed a legitimate Cisco domain through a multi-chain redirect attack designed to evade detection and increase credibility. Campaigns like this show how difficult phishing attacks can be to identify, even for security-aware users.
Devices are expanding the attack surface, as employees now regularly access corporate applications from personal laptops, unmanaged mobile devices, and systems operating outside traditional security controls. Because of this, the IT department has limited visibility into whether employees are connecting to internal networks using devices with missing security updates or malware infections.
Device Trust and Identity-Based Attacks
Compromised endpoints also provide a valuable route into trusted environments. Infostealer malware, in particular, has become a major contributor to account takeover activity by harvesting credentials, browser-stored passwords, and authenticated session cookies directly from user devices.
One of the main reasons account takeover attacks continue to succeed is that many security controls still treat successful authentication as the sole proof of trust. Traditional identity and access management tools are designed to verify credentials and authentication flows, not necessarily whether the person behind them can actually be trusted.
Stopping Modern Account Takeover Attacks
Stopping modern account takeover attacks requires more than validating usernames and passwords. Organizations also need visibility into device posture, session risk, and behavioral signals throughout the entire access lifecycle. That shift is driving greater interest in continuous verification models, where trust is assessed not just at login, but throughout the session.
Specops Device Trust delivers the evolution that Zero Trust identity security requires. By bringing device trust into the equation, security teams have a clearer picture of who’s accessing resources through device authentication, continuous device verification, flexible device coverage, and on-access remediation.
Source: BleepingComputer