Quarterly Threat Report Highlights Identity as Primary Attack Vector

Prophet Security's analysis of all alerts across customer environments from May to July 2026 found that identity was the target in about half of confirmed malicious activity. Session hijacking emerged as the top method for account compromise, with attackers using already-authenticated sessions to bypass standard conditional access controls. The report also details other patterns such as token replay and MFA bypass, noting that password-based attacks were largely blocked by existing security measures.
The investigation encompassed 4.7 million queries across customer systems, with a median of 35 checks per incident. While the vast majority of alerts proved harmless, the malicious subset revealed that attackers frequently bypassed standard protections by exploiting already-validated sessions rather than guessing passwords.
In two separate organizations, deactivating user accounts failed to halt intrusions, as attackers retained access through previously granted permissions and even altered authentication settings. Additionally, rapid cross-border login and approval sequences—occurring within seconds—exposed real-time credential relay infrastructure, while push-notification fatigue tactics successfully coerced approvals in some environments.
This report highlights a shifting vulnerability landscape where traditional password defenses are maturing, but session-based attacks could undermine zero-trust architectures. Organizations relying solely on conditional access policies may find their controls ineffective against stolen tokens, potentially exposing sensitive corporate data and communications. Employees and security teams could face prolonged undetected breaches, as account deactivation may not fully sever attacker access. This trend could drive broader adoption of continuous session validation and real-time behavioral monitoring across industries.