Atlas ApexAtlasApex

Insights

Thinking

Real incidents, industry research, and our perspective on identity architecture.

The Reality

Identity by the numbers

The data is clear. Identity is the primary attack surface, and most organizations aren't ready.

Architecture

79%

of initial-access attacks are malware-free

Up from 40% five years ago. Attackers do not need malware when they have your credentials.

CrowdStrike GTR 2025 ↗
Workforce

67%

of ransomware victims tie the incident to their most significant identity attack

Sophos State of Identity Security 2026, 5,000 organisations surveyed across 17 countries.

Sophos Identity Security 2026 ↗
Enterprise Browser

95%

of organisations have experienced a browser-based attack

Palo Alto Networks research. The browser is where most work happens and where most attacks land — the policy enforcement point belongs there.

Palo Alto / Cybersecurity Dive ↗
Customer Identity

41%

of successful human logins use breached passwords

Cloudflare network telemetry. Roughly half of legitimate logins are indistinguishable from credential-stuffing — design CIAM accordingly.

Cloudflare Research 2025 ↗
Non-Human Identity

98%

of cloud-identity permissions are never used

Sysdig 2024 Cloud-Native Security and Usage Report. Over-permissioned service accounts and machine identities are the cleanest attack surface a credential thief could ask for.

Sysdig 2024 Report ↗
Resilience

8.5M

Windows devices knocked offline by a single faulty update

CrowdStrike Falcon, 19 July 2024 — confirmed by Microsoft. Identity-recovery paths that depend on the same control plane that fails are not recovery paths.

Microsoft Blog (Jul 2024) ↗

Identity Incidents

The Evidence

Real incidents that demonstrate why identity architecture matters. Every one was preventable.

IncidentApr 2026

5.5M

ADT: Vishing → Okta SSO → Salesforce, 5.5M Records

Voice phishing of a help-desk operator compromised Okta SSO credentials. The attacker walked into Salesforce as a legitimate user and exfiltrated 5.5 million customer records. No malware, no zero-day, no credential stuffing — just a phone call.

Source: ADT 8-K filing / BleepingComputer reporting

IncidentApr 2026

78.6M

Rockstar Games: Snowflake Breach via Third-Party Anodot Tokens

ShinyHunters stole authentication tokens that the analytics vendor Anodot held for its customers' Snowflake environments. The attacker queried Rockstar Games' data warehouse using those tokens — looking, to Snowflake, like a normal analytical workload. Over a dozen Anodot customers were caught in the same wave.

Source: TechCrunch / Help Net Security

IncidentMar 2025

$150M

LastPass Breach Leads to $150M Crypto Theft Years Later

Federal prosecutors linked a $150M cryptocurrency heist to the 2022 LastPass breach. Seed phrases stored in Secure Notes were compromised.

Source: KrebsOnSecurity

IncidentJul 2024

Microsoft Entra ID July 2024 Outage: The IdP as Single Point of Failure

A regional Azure / Entra ID disruption in July 2024 blocked sign-ins for thousands of tenants. Microsoft 365, third-party SSO apps, and downstream services that federated to Entra ID all degraded together — exactly because they federated.

Source: Microsoft service health post-mortem

IncidentJul 2024

8.5M

CrowdStrike Falcon Outage: When Identity Recovery Also Goes Down

A single Falcon sensor content update bricked an estimated 8.5 million Windows endpoints worldwide. The recovery story exposed a quieter problem: identity recovery paths assume the endpoints, MFA devices, and IdP integrations are all working.

Source: CrowdStrike Preliminary Post-Incident Review

IncidentJun 2024

165

Snowflake: 165 Customers Breached via Stolen Credentials

Threat actor UNC5537 used infostealer-harvested credentials to access 165 Snowflake customer environments. 80%+ had prior credential exposure. None had MFA.

Source: Mandiant / Google Cloud

Non-Human & AI Identity

The Expanding Surface

Service accounts, API keys, tokens, and AI agents now outnumber human identities by a wide margin. Most are unmanaged.

NHI & AIMay 2026

45:1

The Governance Vacuum Around AI and Non-Human Identity

A Cloud Security Alliance whitepaper finds non-human identities outnumber humans roughly 45 to 1, rising as high as 144 to 1 in cloud-native estates, while only about 15% of organisations feel highly confident they can prevent an NHI-based attack. AI agents make the gap qualitatively worse.

Source: Cloud Security Alliance

NHI & AIMar 2026

29M

GitGuardian Secrets Sprawl 2026: 29M New Secrets, AI Keys Up 81%

29 million new hardcoded secrets reached public GitHub in 2025 — the largest single-year jump GitGuardian has recorded. Leaks tied to AI services rose 81% year-over-year, with 1.27 million AI-service credentials exposed.

Source: GitGuardian — State of Secrets Sprawl 2026

NHI & AIQ1 2026

67%

AI Agents Are the New Non-Human Identity Problem

Sophos's 2026 identity research names weak management of non-human identities — especially the AI agents now multiplying across enterprises — as a primary driver of identity breaches. Two thirds of ransomware victims in the survey traced the incident back to an identity attack.

Source: Sophos / OWASP NHI Top 10 / CSA

NHI & AIDec 2025

ASI03

OWASP's Agentic Top 10 Names Identity Abuse a Core Risk

The OWASP GenAI Security Project's Top 10 for Agentic Applications gives autonomous AI agents a dedicated security benchmark. Identity and Privilege Abuse (ASI03), driven by credential leakage that expands an agent's scope, is named a top category.

Source: OWASP GenAI Security Project

NHI & AINov 2025

25-50x

Non-Human Identity Is Now Its Own IAM Discipline

KuppingerCole's first Leadership Compass for Non-Human Identity Management treats NHI as a distinct, fast-maturing market segment in its own right, not a feature of workforce IAM. NHIs already outnumber human identities by 25 to 50 times.

Source: KuppingerCole

NHI & AIOct 2025

45B+

Agentic AI: The New Frontier of Identity Risk

The WEF highlights that AI agents autonomously spawn NHIs in security blind spots. Only 10% of executives have a strategy for managing AI identities.

Source: World Economic Forum

Frameworks

Through the Identity Lens

Compliance frameworks read for the identity controls that decide whether the rest works. Authoritative sources linked on each page.

Industry Research

The Numbers

Key findings from the industry's most authoritative security reports.

ResearchMay 2026

22%

Verizon DBIR 2026: Credentials Still #1, Infostealers Industrialised

The 2026 Verizon Data Breach Investigations Report keeps credentials at the top of the initial-access list for the second year running. 88% of web-application attacks use stolen credentials. Infostealers compromised 30% of corporate and 46% of unmanaged devices holding company credentials.

Source: Verizon

ResearchMay 2026

71%

Sophos 2026: 71% of Organisations Hit by an Identity Breach

Sophos surveyed 5,000 IT and cybersecurity leaders across 17 countries for its State of Identity Security 2026. 71% suffered at least one identity-related breach in the previous year, with an average of three incidents. 67% of ransomware victims confirmed the incident started with an identity attack.

Source: Sophos — State of Identity Security 2026

ResearchOct 2025

99%+

Microsoft: Phishing-Resistant MFA Stops 99%+ of Identity Attacks

Microsoft's Digital Defense Report confirms phishing-resistant MFA (FIDO2/passkeys) stops over 99% of identity attacks. 97% of attacks are password spray.

Source: Microsoft

ResearchJul 2025

$4.81M

Credential Breaches Cost $4.81M and Take 292 Days to Detect

Credential-based breaches are the most common, most expensive, and slowest to detect. The worst possible combination.

Source: IBM / Ponemon Institute

ResearchH2 2025

47%

Google Cloud: 47% of Cloud Incidents From Weak Credentials

Weak or absent credentials account for nearly half of all cloud compromises. Identity is the dominant cloud attack surface.

Source: Google Cloud Security

Research2025

18B

SpyCloud 2025: 18 Billion Stolen Credentials Tracked

SpyCloud's intelligence platform tracks credentials harvested by infostealer malware and aggregated into the criminal ecosystem. The 2025 report puts cumulative tracked credentials past 18 billion, with infostealer-derived corporate credentials a fast-growing slice.

Source: SpyCloud Annual Identity Exposure Report

Analyst Insights

The Market View

What Gartner, Forrester, and the major analyst firms are saying about identity security.

AnalystFeb 2026

KuppingerCole: IAM 2026 and the Rise of AIdentity

KuppingerCole's Research Compass for IAM 2026 advances the Identity Fabric architecture and positions AI as increasingly integral to identity itself. The firm's framing of autonomous, AI-driven identity systems for managing high-volume machine identities puts architecture, not product, at the centre.

Source: KuppingerCole Research Compass (AN82012)

AnalystNov 2025

$27.5B

Forrester: IAM Investment to Double to $27.5B by 2029

IAM spending is projected to nearly double from $13.4B (2024) to $27.5B by 2029, driven by machine identity and AI governance needs.

Source: Forrester Research

AnalystNov 2025

KuppingerCole Leadership Compass: The ITDR Market Takes Shape

KuppingerCole's November 2025 Leadership Compass on Identity Threat Detection and Response (LC81209, Alejandro Leal) is a vendor comparison of a market that, three years ago, did not have a name. The category's existence is itself the finding worth reading.

Source: KuppingerCole Leadership Compass (LC81209)

Analyst2025

IDC FutureScape 2025: Identity Spending to Outpace Network by 2027

IDC's FutureScape research projects that identity-security spending will exceed traditional network-security spending in the enterprise budget mix by 2027. The shift tracks the move of the security perimeter from network to identity.

Source: IDC FutureScape — Worldwide Future of Trust

AnalystJun 2025

40%

Gartner: Over 40% of Agentic AI Projects Cancelled by 2027

Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027, driven by escalating costs, unclear business value, or inadequate risk controls. The same firm names agentic AI its headline strategic technology trend. Both can be true at once.

Source: Gartner press release (Jun 2025)

Analyst2025

KuppingerCole: What CIAM Has to Mean in 2025

KuppingerCole's session on how to do CIAM in 2025 and beyond, led by analyst John Tolbert, defines customer identity broadly: not a login box, but registration, consent, fraud signals, progressive profiling, and identity assurance across the full customer relationship.

Source: KuppingerCole webinar (John Tolbert)

ATLAS Apex Perspective

Our View

Our take on identity architecture, resilience, and the discipline behind the controls. Written in-house, not assembled from analyst summaries.

PerspectiveMay 2026

Identity Recovery Is Its Own Workflow

Most disaster-recovery plans assume identity will be working when the rest of the estate is not. That assumption fails the first time identity itself is the affected service — which now happens every quarter.

Source: ATLAS Apex perspective

PerspectiveMay 2026

The Browser Is the New Endpoint

The endpoint is no longer the place enterprise work happens. The browser is. The control surface that used to live on the device — DLP, posture, session controls, identity-aware enforcement — has to live where the work runs.

Source: ATLAS Apex perspective

PerspectiveMay 2026

Architecture Survives Incidents. Configurations Do Not.

Most identity incidents do not have a root cause in the platform configuration. They have a root cause in the architectural assumption the configuration was implementing.

Source: ATLAS Apex perspective

PerspectiveMay 2026

Identity Mesh Beats Identity Federation

Federation is the old framing: one IdP at the centre, downstream relying parties consuming its decisions. Identity Mesh is the working framing for what is now actually in production: many identity services and the signals between them, composed into a control plane.

Source: ATLAS Apex perspective

PerspectiveMay 2026

The Okta Tenant Resilience Gap

Identity tenants get treated like SaaS — "the vendor will look after it" — until the day a configuration mistake, an insider action, or a token compromise needs to be undone. By then the recovery options are weeks of forensics or a fresh tenant.

Source: ATLAS Apex perspective

Have a perspective to share?

We're always interested in conversations about identity architecture. If you have a view, we'd like to hear it.

Start a Conversation