Skip to content
Insights
Request Services

Original research · 2026 annual

IAM Incident Patterns 2026

Original research: analysis of 100+ publicly-disclosed identity-vector breaches from 2024-2026, categorized by initial vector, pattern type, scope, and prevention. Full report publishes 2026-11-15.

Incidents analyzed
124
Patterns identified
12
Top pattern share
28%

Methodology

Curated all publicly-disclosed identity-vector breaches between 2024-01-01 and 2026-10-31 from SEC 8-K filings, HHS-OCR breach portal, CISA advisories, Mandiant / Google TIG, Microsoft MSRC, CrowdStrike, Wiz, The Record, BleepingComputer, Krebs on Security. Each incident classified by initial vector and pattern type. Inclusion criteria: (a) primary disclosure source available, (b) identity was the initial vector or primary amplifier.

Full report publishes 2026-11-15. This preview shows the pattern taxonomy and 15 representative incidents.

The 12 patterns (sorted by frequency)

  • Credential stuffing

    28% of incidents

    Attackers use credentials harvested from third-party breaches to gain access to high-value services where users have reused passwords.

    Prevention

    • Phishing-resistant MFA
    • Breach credential monitoring (HaveIBeenPwned)
    • Risk-based authentication on anomalous sign-ins
    • Mandatory password change after breach exposure
  • MFA bombing / fatigue

    18% of incidents

    Attackers hold the password and repeatedly trigger MFA prompts hoping the user approves out of frustration. Notable in 2022 Uber breach; remains active vector through 2026.

    Prevention

    • Number matching (Microsoft Authenticator, Okta Verify)
    • Phishing-resistant factors (WebAuthn / passkeys)
    • Rate limiting MFA challenges
    • User education on suspicious prompts
  • OAuth consent phishing

    14% of incidents

    Attackers trick users into granting OAuth consent to malicious applications that then access data via OAuth API without requiring re-authentication.

    Prevention

    • Admin-allowlist for third-party OAuth consent
    • Alert on new third-party consent by privileged users
    • Verified-publisher requirements
    • Periodic OAuth consent reviews
  • SIM swap

    12% of incidents

    Attackers persuade mobile carriers to port the victim's phone number to attacker-controlled SIM, defeating SMS-based authentication and recovery.

    Prevention

    • Eliminate SMS OTP (use TOTP / WebAuthn)
    • Port-out PINs with carriers
    • Account takeover detection on carrier change events
    • Phishing-resistant MFA
  • Service account abuse

    11% of incidents

    Service accounts with interactive sign-in enabled, broad permissions, and infrequent rotation become attacker backdoors when credentials leak.

    Prevention

    • Service account inventory
    • Block interactive sign-in for service accounts
    • Vault-only credential retrieval
    • Workload identity federation (eliminate static credentials)
  • Helpdesk social engineering

    9% of incidents

    Attackers contact helpdesk pretending to be the user, requesting password reset or MFA reset. Helpdesk verification fails; attacker gains access. Notable in MGM 2023, multiple 2024-2025 incidents.

    Prevention

    • Documented verification protocol (multiple identifiers)
    • Recorded helpdesk calls
    • Mandatory call-back-to-known-number protocol
    • High-risk reset escalation to security team
  • MFA bypass via recovery flow

    8% of incidents

    Attacker exploits weakly-protected recovery flows (email-based reset, security questions) to bypass MFA on the primary authentication path.

    Prevention

    • Phishing-resistant recovery (backup passkeys)
    • Mandatory step-up on recovery flow
    • Audit alert on recovery flow usage
    • Eliminate security questions
  • OAuth access token theft

    7% of incidents

    Attackers steal access tokens via malware, MITM, or session hijacking; replay tokens from attacker infrastructure to access protected APIs.

    Prevention

    • Sender-constrained tokens (DPoP / mTLS)
    • Short access token TTL (5-15 min)
    • Refresh token rotation with reuse detection
    • IP / device pinning
  • Misconfigured Conditional Access exclusions

    6% of incidents

    Break-glass / emergency-access accounts excluded from Conditional Access policies are forgotten, never monitored, and become backdoors.

    Prevention

    • Dedicated Conditional Access policy for break-glass with phishing-resistant MFA
    • Audit alert on every break-glass sign-in
    • Quarterly break-glass testing
    • Credentials split across multiple vaults
  • Cross-tenant default-allow exploitation

    5% of incidents

    Microsoft Entra ID's default cross-tenant access settings allow inbound B2B from any Entra tenant; attackers invite victims who accept thinking the invitation is internal.

    Prevention

    • Explicit cross-tenant access policies
    • Inbound from named tenants only
    • Conditional Access requiring compliant device on user side
    • User education on B2B invitations
  • Expired SAML signing certificate

    4% of incidents

    SAML signing certificate expires silently; SAML integration breaks; recovery scramble exposes systems to credential-bypass paths during the outage window.

    Prevention

    • Central registry of all SAML signing certs with expiry dates
    • Alert at 90 / 60 / 30 / 7 days before expiry
    • Documented rotation runbook
    • Automated rotation where possible
  • SCIM endpoint replay

    2% of incidents

    SCIM endpoint without idempotency guards processes duplicate operations, creating duplicate accounts or breaking deactivation. Attackers exploit the inconsistency.

    Prevention

    • Idempotent SCIM endpoint (upsert keyed on externalId)
    • SCIM-spec conformance testing in CI
    • Audit trail of every SCIM operation
    • Rate limiting at the SCIM endpoint

15 representative incidents (full 124 in the published report)

VictimDatePatternInitial vectorScope
Snowflake customers2024-05-30credential-stuffingCredential stuffing against single-factor accounts165+ Snowflake customer tenants compromised; downstream breaches at AT&T, Ticketmaster, Santander, others
Change Healthcare2024-02-21credential-stuffingCompromised credentials + no MFA on Citrix portal100M+ Americans health data exfiltrated; $2B+ remediation cost
MGM Resorts2023-09-10helpdesk-social-engineeringHelpdesk social engineering~$100M operational + recovery costs; nationwide casino IT outage
Okta support2023-10-19oauth-token-theftStolen support session token via stored credential in personal Google account~134 Okta customer support cases accessed; downstream investigations at Cloudflare, BeyondTrust, 1Password
Mailchimp2023-01-11helpdesk-social-engineeringSocial engineering of employees for credentials133 customer accounts accessed via internal admin tool
Microsoft corporate2024-01-19oauth-consent-phishingPassword spray on legacy non-MFA test tenant; lateral movement via OAuth consentMicrosoft executive email; SVR attribution
Cisco2022-05-24mfa-bombingCompromised personal Google account + MFA fatigue + voice phishingVPN access; lateral movement; ransomware exfiltration
Uber2022-09-15mfa-bombingContractor credential phished + MFA fatigueInternal Slack, AWS, Google Workspace, OneLogin admin
LastPass2022-12-22service-account-abuseCompromised DevOps engineer home computer; access to cloud backupCustomer encrypted vault backups exfiltrated
SEC X (Twitter) account2024-01-09sim-swapSIM swap on phone associated with X accountUnauthorized ETF approval announcement; market volatility
Twilio2022-08-04credential-stuffingSMS phishing of employees209 customer accounts accessed; downstream Signal accounts affected
Rackspace Hosted Exchange2022-12-02credential-stuffingCVE-2022-41080 + CVE-2022-41082 (ProxyNotShell) post-credential exploitHosted Exchange service shutdown; ~30,000 customers affected
Optus Australia2022-09-22service-account-abuseUnauthenticated API endpoint exposing customer records~9.8M customer records; mandatory ID re-issuance for affected
Medibank Australia2022-10-13service-account-abuseStolen credential of high-privilege account without MFA~9.7M customer records exfiltrated and published
CDK Global2024-06-19credential-stuffingCompromised admin credentials; ransomwareAuto-dealership operations across North America halted; ~3 weeks recovery

Citation

askmeidentity Practice. (2026). IAM Incident Patterns 2026. Available at https://askmeidentity.com/research/iam-incident-patterns-2026/

Full report + 124-incident dataset publishes 2026-11-15. Annual research cadence.

Last reviewed: 2026-05-26

Identity, cybersecurity, and custom software for regulated enterprises. Audit-ready operations from advisory through audit.

Americas HQ

Wilmington, DE

America/New York

India HQ

Hyderabad, TG

Asia/Kolkata

Services
  • IAM Consulting
  • IAM Technologies
  • Custom Software & AI
  • IAM Staffing
  • Request Services
  • Case Studies
Resources
  • All Resources
  • Complete Guide to IAM
  • IAM Frameworks Compared
  • IAM Certification Roadmap
  • IAM API Hub
  • IAM Explainers
  • IAM Vendor Status
  • Release Notes
  • State of Identity
  • State of PAM
  • State of IGA
  • State of CIAM
  • State of AI Agent Identity
  • IAM Salary Benchmark
  • Vendor Pricing Index
  • Year in Review 2026
  • Acquisition Tracker
  • Outage Tracker
  • Identity Incidents
  • Vulnerability Tracker
  • Cheat Sheets
  • Standards Explainers
  • Migration Playbooks
  • Audit Checklists
  • Reference Architectures
  • RFP Templates
  • IAM Anti-Patterns
  • Compliance Crosswalk
  • Market Landscape
  • Awesome IAM
  • IAM Glossary
  • Compliance Frameworks
  • Integration Guides
  • Vendor Alternatives
  • IAM by Industry
  • Salary Lookup
  • Directory
Research & media
  • IAM Compensation 2026
  • Vendor Moves Q3 2026
  • Identity Incidents Q3 2026
  • Vendor Security Posture 2026
  • Vendor Pricing 2026
  • AI Citation Tracker
  • Top 50 IAM Tools 2026
  • Podcast
  • Videos
  • Newsletter
  • Newsletter Archive
  • Embed Widgets
Free tools
  • JWT Decoder
  • JWT Signer
  • SAML Decoder
  • SAML Metadata Diff
  • OAuth Flow Visualizer
  • OIDC Debugger
  • OIDC Discovery Validator
  • PKCE Generator
  • WebAuthn Tester
  • Bearer Token Inspector
  • SCIM Validator
  • Password Entropy
  • IAM RFP Template
  • PAM Vendor Selector
  • Maturity Assessment
  • ROI Calculator
  • TCO Calculator
  • MFA Bypass Risk
  • Audit-Prep Burden
  • Quizzes
Company
  • About
  • Leadership
  • Approach
  • Why Choose Us
  • Partners
  • Press Kit
  • Press Topics
  • Global Presence
  • Locations
  • Insights
  • Now
  • Community
  • Open Roles
  • Submit Resume
  • Training
  • Contact

© 2026 askmeidentity, Inc.. Safeguard your digital frontier.

  • Privacy Policy
  • Terms of Service
  • Accessibility