It’s not a secret that phishing, stolen credentials, and human error remain some of the easiest ways for attackers to get into an environment. Identity has become one of the biggest attack surfaces for organizations today because sometimes, all an attacker needs to do is log in. That access can come from valid credentials, stolen sessions, exposed tokens, compromised service accounts, or abused application permissions. Some of that identity material is stolen through phishing, collected by infostealers, purchased from initial access brokers (IAB), exposed in code repositories, or traded on underground markets. This report looks at how those identity-related access pathways are showing up across Bitsight Threat Intelligence over the past year.
Not every result in this dataset is a confirmed breach caused by identity theft, because it's not that simple. Instead, this analysis looks at where breach, intrusion, compromise, and unauthorized-access terms appear alongside identity-related activity. In other words, where are we seeing identity show up around breach and access-related threat intelligence?
Non-human identity exposure, including API keys, tokens, service accounts, and hardcoded credentials
The largest signal came from non-human identity exposure, with 42,189 results tied to API keys, access tokens, service accounts, secret keys, SSH keys, cloud keys, and hardcoded credentials. To be clear, that does not mean 42,189 confirmed breaches caused by exposed tokens, however, it does show a major exposure problem. Since 36,466 of those results came from code repositories, this points to exposed secrets and developer identity risk as a major part of the modern identity attack surface.
Signal volume across five risk categories over the past 12 months
67,145
TOTAL RESULTS
Non-human identity exposure
42,18962.8%
Stolen and compromised credentials
15,22822.7%
MFA and session bypass
5,1427.7%
Infostealers
4,2076.3%
OAuth consent abuse
3790.6%
The clearest traditional identity breach signal came from stolen and compromised credentials, which returned 15,228 results over the past year. This is the category that most closely lines up with attackers using stolen, reused, compromised, or otherwise valid credentials to gain unauthorized access.
Infostealers and MFA/session bypass also showed meaningful activity. The infostealer category returned 4,207 results and included malware families like RedLine, Raccoon, Lumma Stealer, and Vidar. These tools help attackers collect the identity material they need before trying to access an environment, including credentials, cookies, sessions, and tokens.
MFA and session bypass returned 5,142 results. This points to active discussion, tooling, and reporting around session hijacking, cookie theft, token theft, token reuse, MFA fatigue, and other ways attackers try to work around authentication controls.
OAuth consent abuse had the smallest signal, with 379 results. This is a more specific cloud and SaaS identity risk where attackers may abuse malicious OAuth apps, consent phishing, application permissions, or illicit consent grants to gain access without directly stealing a password.
AI is also starting to change this landscape. While it doesn't replace identity attacks, it can make them easier to scale. Attackers can use AI to write better phishing lures, profile targets, process stolen data faster, automate reconnaissance, and turn stolen credentials, sessions, and tokens into usable access more efficiently. This report does not fully analyze AI-enabled identity abuse, but it is an important follow-on area because AI may accelerate the identity attack surface organizations already have.
Identity compromise is not just about stolen usernames and passwords anymore. Attackers are also using infostealers, sessions, tokens, OAuth permissions, service accounts, API keys, and hardcoded credentials. Identity security now has to cover the full ecosystem of human and non-human access.
Analysis approach: 5 identity-related pathways
This analysis is based on identity-related threat intelligence observed in Bitsight Threat Intelligence over the past year. The goal was to understand where identity-related activity appeared alongside breach, intrusion, compromise, unauthorized-access, or incident-related language.
The analysis focused on five identity-related access pathways:
Identity-related access pathway
Focus area
Total results
Non-human identity exposure
API keys, API tokens, access tokens, service accounts, secret keys, SSH keys, cloud keys, hardcoded credentials
These results should be treated as identity-related breach indicators, not confirmed breach counts. The main analysis intentionally focused on places where identity-related terms appeared alongside breach, intrusion, compromise, unauthorized-access, or incident-related language. That is why the numbers in the main table are lower than broader marketplace or forum searches.
The follow-up searches were intentionally broader and were not designed to identify breach-adjacent results. Those searches looked more broadly at credential, access-market, session, OAuth, and exposed-secret language across underground sources and other threat intelligence data. They returned much higher volumes, but they also captured more general marketplace chatter, tooling, logs, advertisements, reporting, and discussion that may not be tied to a specific breach.
Because of that, the main numbers should be read as breach-adjacent identity indicators. The broader follow-up searches should be read as underground context for how identity material is discussed, tested, traded, and monetized, not as evidence that each result is tied to a breach.
1. Stolen and compromised credentials are still the clearest identity access pathway
The stolen credentials category returned 15,228 results, making it the strongest traditional identity-related breach signal after setting aside the much noisier non-human identity bucket. That lower number is intentional: this search focused on identity language tied to breach, intrusion, compromise, unauthorized access, or similar incident terms.
A separate follow-up search across ransomware markets and forums returned more than 3 million results tied to stolen credentials, stolen logins, passwords, or credential-related language. That number should not be read as breach volume, especially because broad terms like “password” and “credentials” capture marketplace chatter, tools, logs, and general discussion. But it does reinforce the bigger point: identity material is deeply embedded in the underground economy, and ransomware-adjacent actors continue to rely on credentials to validate access, enable account takeover, and move toward higher-value intrusions.
A supplemental credential validation search returned 331,335 results when limited to ransomware-related sources, leak sites, and illicit marketplaces. That included terms tied to checkers, combo lists, account checkers, credential stuffing, password spraying, hits, and valid logins. The broader all-source number was much higher, but also much noisier. The point is not that every result is a breach. The point is that attackers are not just collecting credentials but rather, testing which ones still work.
This lines up with what we saw in Bitsight’s 2026 State of the Underground report too: Bitsight observed 2.8 billion unique compromised credentials in 2025, and credential volumes grew at a 92% compound annual rate from 2022 to 2025. A separate access-market follow-up search adds another layer. Terms like “access for sale,” “VPN access,” “RDP access,” “Citrix access,” “domain admin,” “corporate access,” “panel access,” and “logs for sale” returned 2,736 results when limited to ransomware-related sources and marketplaces, and 483,677 results across all sources.
These results should not be compared directly to the breach-adjacent credential count, but they show why stolen credentials matter: attackers are not only collecting identity material, they are looking for ways to turn it into usable corporate access. So even though this report is not treating every credential-related result as a breach, the broader point is hard to ignore. There is a massive amount of identity material already out there, and attackers only need some of it to still work. They may not need to exploit a system if they can log in with credentials that already open the door. Those credentials may be stolen, reused, purchased, dumped, or pulled from older breaches, but the result is often the same: access that looks legitimate at first glance.
Figure 1: Example of access-validation tooling observed in Bitsight Threat Intelligence within the past year. Tools like this help attackers test whether credentials provide usable access to RDWeb or RDP environments, turning stolen or purchased credentials into a possible intrusion path.
2. Infostealers feed the identity compromise ecosystem
The infostealer category returned 4,207 results over the past year. This shows how attackers may get the identity material they need before they ever try to access an organization. Infostealers collect credentials, browser cookies, session data, tokens, and account information. The top malware families in this category included RedLine, Raccoon, Lumma Stealer, and Vidar, all of which are tied to credential and session theft. Identity theft is no longer just a username-and-password problem.
If an attacker can steal a session cookie or token, they may be able to get around normal login flows entirely. Infostealers appear to play a major role in the identity compromise ecosystem by collecting credentials, cookies, sessions, and tokens that can later be used for unauthorized access.
Figure 2: Example of stealer-style tooling observed in Bitsight Threat Intelligence within the past year.
3. MFA matters, but attackers are targeting what happens after login too
MFA is a strong defense against credential attacks, but attackers are not only trying to steal passwords anymore. The MFA and session bypass category returned 5,142 results tied to MFA bypass, MFA fatigue, push bombing, OTP theft, session hijacking, session cookies, cookie theft, token theft, and token reuse.
A separate follow-up search around cookies, session cookies, session tokens, browser profiles, fingerprints, anti-detect tooling, stealer logs, and token reuse returned 2,483,133 results across all sources, with 121,371 results found in leak sites and illicit marketplaces. These broader numbers should not be compared directly to the breach-adjacent count, but they reinforce the same point: attackers are paying close attention to the post-authentication layer.
Passwords still matter, but sessions, cookies, tokens, browser profiles, and device fingerprints can also become paths to access. Even when MFA is in place, attackers may try to hijack authenticated sessions, reuse tokens, steal cookies, or pressure users through MFA fatigue and push-bombing tactics. Stealing the right session token or cookie can give attackers access to an already authenticated session.
This category also needs caution. Some of the signal came from code repositories, which means some results may include scripts, proof-of-concept material, tools, or technical references rather than confirmed incidents.
While MFA is still a critical control, attackers are also focused on sessions, cookies, tokens, and MFA workflows. This should be treated as evidence of active tooling and discussion, not a direct count of MFA-related breaches.
Figure 3: Example of live session phishing-style tooling with controls for captured forms, cookies, storage, and session interaction. This shows why identity attacks increasingly extend beyond stolen passwords.
4. OAuth consent abuse is smaller, but it is a real cloud and SaaS risk
OAuth consent abuse returned 379 results, making it the smallest category in the analysis. A separate follow-up OAuth and cloud identity search returned 1,026,818 results across all sources, and 49,218 results when limited to ransomware-related sources, marketplaces, and forums. Those numbers are not directly comparable to the 379 breach-adjacent OAuth consent abuse results in the main analysis, but they show that OAuth tokens, refresh tokens, app passwords, backup codes, TOTP setup, passkeys, Azure AD, M365, and Google Workspace are being discussed at much greater volume across the broader threat landscape. In other words, OAuth abuse may be a smaller breach-adjacent signal, but cloud identity and post-login access are clearly part of attacker interest.
That doesn't make it less important than the others, rather just more specific. It is expected to appear less often than broader categories like stolen credentials or exposed tokens. Again, attackers can get access without directly stealing a password. Instead, they may abuse OAuth consent flows, malicious apps, consent phishing, application permissions, or illicit consent grants. The top products associated with this category included Azure, Microsoft 365, Azure AD, M365, and OneDrive, which reinforces that this risk is closely tied to cloud identity and SaaS environments. OAuth consent abuse appears less often than other identity-related pathways, but it highlights an important risk where attackers may gain access through application permissions instead of directly stealing credentials.
Figure 4: Example of identity-focused tooling observed in Bitsight Threat Intelligence within the past year, including payloads for OAuth tokens, app passwords, backup codes, passkeys, and TOTP setup. This shows how attackers may target cloud identity workflows, authentication controls, and post-login access mechanisms.
5. Non-human identities are the biggest exposure story, but they need context
Non-human identity exposure returned 42,189 results, the highest volume across all five categories. This includes activity tied to API keys, API tokens, access tokens, service accounts, secret keys, SSH keys, cloud keys, and hardcoded credentials. This is a major exposure surface. Service accounts, API keys, access tokens, SSH keys, and hardcoded credentials can provide powerful access, especially when they are overprivileged, poorly monitored, or accidentally exposed.
A separate follow-up search reinforces how widespread this issue is. Terms tied to exposed secrets, including .env, AWS keys, GitHub tokens, private keys, SSH keys, service accounts, API tokens, cloud keys, and access keys, returned 2,859,679 results across all sources and 8,320 results in targeted forums and ransomware-related sources. Those broader numbers should not be compared directly to the breach-adjacent count, but they do show that non-human identity exposure is not just a code hygiene issue. It is part of the underground access economy. This bucket needs the most caution. Code repositories accounted for 36,466 of the 42,189 total results. Because of that, this should not be framed as “42,189 breaches caused by tokens.” That would overstate the finding.
A more accurate analysis is that Bitsight Threat Intelligence is surfacing a large amount of non-human identity exposure and secrets-related risk, especially in developer and code environments. Secrets can end up in repositories by accident when developers hardcode API keys, access tokens, SSH keys, cloud secrets, service account files, connection strings, or environment variables into source code, configuration files, scripts, CI/CD workflows, test files, or deployment templates. These are not always username-and-password pairs, but they can still function like access keys. If they are exposed and still active, attackers may be able to use them to access cloud environments, CI/CD pipelines, source code, production systems, or connected third-party services. So while this should not be treated as confirmed breach activity, it should not be dismissed as noise either. It shows where attackers may find reusable access before an intrusion ever starts. In other words, an exposed secret in a repository may not be a confirmed breach, but it can make one possible.
Public reporting on TeamPCP and Mini Shai-Hulud shows how exposed developer and non-human identities create real world risk. TeamPCP has carried out repeated software supply chain attacks involving malicious code inserted into legitimate developer tools, with Mini Shai-Hulud described as self-replicating malware that spreads by stealing credentials and embedding itself into other software. Other reporting on Mini Shai-Hulud described attacks against npm and developer ecosystems that used stolen login credentials and access tokens to publish malicious packages and target GitHub, cloud, and CI/CD secrets.
Confidence layer
Identity-related threat intelligence can include a lot of different material, and not all of it means the same thing. A named extortion post claiming stolen records from a specific company would be treated as stronger breach-related evidence. It has a victim, a claim, and clear incident language. But even then, it still needs review before saying identity was the initial access method.
A screenshot of access tooling, a malware advertisement, or a suspicious wallet page may still matter, but it should not automatically be counted as a confirmed breach. Those results may point to identity exposure, fraud, malware, or access risk, but they do not always prove identity-driven breach activity.
For this reason, results should be separated into three categories:
Category
Definition
Use in report
Confirmed or likely breach
Named victim, data theft, extortion, unauthorized access, leaked records, or clear incident language
Use as breach-related evidence
Identity exposure or abuse indicator
Credentials, tokens, sessions, phishing, infostealers, service accounts, access tools, or suspicious infrastructure
Use as identity-risk evidence
Noise or weak match
Generic code, tools, malware ads, unrelated crimeware, or unclear references
Exclude from breach claims or use only as context
Conclusion
Identity risk is broad, layered, and increasingly tied to both human and non-human access. Stolen and compromised credentials remain one of the clearest identity-related access pathways. Infostealers add another layer by giving attackers credentials, cookies, sessions, and tokens that can be reused later.
MFA is still important, but attackers are also looking for ways around authentication controls through session hijacking, token theft, cookie theft, and MFA bypass techniques. OAuth consent abuse appears less often, but it highlights a cloud and SaaS risk where attackers can gain access through malicious application permissions instead of stolen passwords.
Non-human identity exposure produced the highest result volume overall, but the heavy concentration of code repository results means this should be treated as exposed secrets and developer identity risk rather than confirmed breach causality.
AI will likely make this problem harder. It can help attackers write more convincing lures, organize stolen data, identify valuable accounts, automate parts of reconnaissance, and move faster from exposed identity material to usable access. That does not mean every identity attack is AI-enabled, but it does mean identity defenders should expect speed and scale to keep increasing. AI may not create a brand-new identity problem as much as accelerate the one organizations already have.
Identity security needs to be treated as a full attack surface. Organizations should look beyond passwords and MFA alone and focus on credential hygiene, phishing-resistant MFA, session monitoring, token protection, OAuth permission governance, service account management, and secret scanning across code repositories.
The biggest takeaway is that identity compromise is no longer just about stolen usernames and passwords. It now includes the broader ecosystem of credentials, sessions, tokens, applications, and non-human identities that attackers can abuse to gain access.
Report: Exposed AI Services Surged 360% In 2025 & more
The attack surface is expanding as AI becomes more embedded in enterprise and attacker workflows. Get the full picture on AI exposure, exploit pressure, and the underground trends security teams need to watch.
A critical vulnerability, CVE-2026-76460, affecting Cisco ISE & ISE-PIC is being actively exploited. Read more for technical details & impact to organizations.
Bitsight discusses at 3 phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, & email phishing.