Identity & Access

Credential Theft

Stolen credentials are the most common breach starting point.

What it is

Attackers obtain valid credentials through phishing, password spraying, credential stuffing from leaked databases, or keyloggers. Stolen credentials remain the top initial access vector according to the Verizon DBIR 2025, appearing in the majority of hacking-related breaches. Unlike malware, credential-based intrusion produces no malware signatures and blends into normal authentication logs.

Attack techniques

  • Phishing (T1566)
  • Credential Stuffing (T1110.004)
  • Password Spraying (T1110.003)
  • Adversary-in-the-Middle phishing kits (T1557)
  • Keylogging (T1056.001)
  • LSASS Memory Dumping (T1003.001)

Business impact

An attacker with valid credentials can authenticate to any system that account has access to — bypassing firewalls, VPNs, and most monitoring that looks for malware rather than authenticated sessions.