Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Prophet Security identifies identity attacks as a leading threat

Prophet Security investigated every alert in customer environments from May 1 through July 31, 2026. Of completed investigations, 93% were benign and 7% were confirmed malicious. The findings were based on 4.7 million questions, with a median of 35 questions per investigation.

Identity was the target in roughly half of confirmed malicious activity. Direct attacks on accounts and sessions represented about 18%, while credential phishing was the largest single category at about 28%. Malicious code execution and tooling accounted for about 23%.

Attackers using passwords were usually blocked by security controls, but already-authenticated sessions repeatedly succeeded. In some cases, accounts saw dozens of malicious sign-ins over three weeks. One phishing sequence showed a login from one country followed by an MFA approval from another after 16 seconds, and again after 118 seconds.

Infostealers affected roughly a quarter of investigated organizations and were mostly delivered through browsers. Trojanized installers were found at about a quarter of organizations. Prophet Security said attackers used compromised websites, malicious ads, fake CAPTCHA gates known as ClickFix, and fake updates. SocGholish infrastructure was disrupted on June 18, 2026, under Operation Endgame, but its fake-update model continued through ClearFake.

Phishing campaigns often targeted financial roles. One finance executive faced dozens of campaigns over three months, while another recipient received near-identical emails from different domains twice in two weeks.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.