Fragmented shield and lock symbols in teal and grey tones, representing compromised identity and broken security controls

Unit 42: “Identity Has Become the Most Reliable Path to Attacker Success”

Palo Alto Networks’ Unit 42 team published new incident-response data showing why defenders should prioritize identity.

The “2026 Unit 42 Global Incident Response Report” draws on more than 750 incident-response engagements across over 50 countries in 2025. Its central finding for zero-trust programs: identity weaknesses played what the team calls a material role in almost 90% of investigations, with intruders increasingly logging in on stolen credentials and tokens rather than breaking in. The report frames it bluntly: “Identity has become the most reliable path to attacker success.”

In 87% of intrusions, attacker activity spanned multiple surfaces at once, endpoint, network, cloud, SaaS, and identity, and 48% involved browser-based actions tied to routine email and web workflows. In more than 90% of breaches, the report attributes the intrusion to preventable gaps: thin visibility, inconsistent controls, or excessive identity trust.

The report also states that exfiltration speeds for the fastest attacks quadrupled in 2025, which it attributes to AI compressing the attack lifecycle. The primary text does not publish the absolute time behind that multiplier, so treat the multiplier, not any specific minute figure, as the verified claim.

For enterprise and federal leaders benchmarking zero-trust maturity, the read is direct. Cross-surface intrusions undercut siloed tooling, and a shrinking containment window rewards continuous verification, least privilege, tight credential and token hygiene, and consolidated telemetry. The vendor sells IR, XDR and identity products, so weigh its remedies against your own architecture, but the underlying pattern maps cleanly to known zero-trust gaps.


Leave a Reply

Discover more from Digerati One (Di1) | AI Integration & Multi-Cloud Architecture

Subscribe now to keep reading and get access to the full archive.

Continue reading