Contacts
Book a Meet
Close

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Contacts

Bulgaria, Kavarna
Saudi Arabia, Riyadh

+359 875 328030

sales@diamatix.com

Attack #2: Credential Abuse & Account Takeover

DIAMATIX_Post_....01.2026 - Copy

Attack #2: Credential Abuse & Account Takeover

Threat snapshot – Credential Abuse & Account Takeover

CategorySummary
What it isAttacks where stolen or leaked credentials are used to access systems as legitimate users and move inside the environment without exploiting vulnerabilities.
Most common targetsCloud services, VPNs, email platforms, admins, finance and operations teams, remote access infrastructure.
What it relies onStolen credentials, lack of MFA, excessive privileges, weak identity monitoring, and poor access hygiene.
How it’s detectedAbnormal logins, impossible travel, new devices, privilege changes, behavioral anomalies.
Primary impactPersistent access, lateral movement, privilege escalation, data theft, ransomware staging.
What realistically helpsStrong identity security, MFA everywhere, least privilege, continuous monitoring, and fast containment playbooks.

How the attack works

Credential abuse does not break systems. It uses them.

Once valid credentials are obtained. through phishing, malware, data leaks, or third-party breaches. attackers no longer need to “hack.” They log in.

From the outside, the activity looks legitimate. Correct usernames. Correct passwords. Often from realistic locations and devices. This is why credential abuse remains one of the hardest attack stages to detect.

Account takeover turns identity into the attack vector.

Real-World Cases

Credential abuse and account takeover attacks use valid passwords, sessions, or login approvals. This allows attackers to appear legitimate and bypass some standard security controls.

Uber (2022)

Sector: Technology and Transportation

How did the incident begin?
The attacker used a corporate password belonging to an external contractor, likely exposed after malware infected the contractor’s personal device. After repeated login attempts, the contractor approved one MFA (Multi-Factor Authentication) request.

What was compromised?

  • employee accounts;
  • internal tools, including Slack and Google Workspace;
  • some internal messages and finance-related information.

How did the attack develop?
The attacker accessed additional employee accounts and gained elevated permissions. Uber blocked affected accounts, disabled some internal tools, and rotated access keys.

What could have reduced the impact?

  • phishing-resistant MFA;
  • protection against MFA fatigue;
  • device and login-context verification;
  • least-privilege access.

23andMe (2023)

Sector: Genetic and Consumer Services

How did the incident begin?
The attacker used credential stuffing — automated login attempts with usernames and passwords compromised elsewhere and reused on 23andMe. The company found no evidence that its own authentication systems had been breached.

What was compromised?

  • approximately 14,000 accounts;
  • around 5.5 million DNA Relatives profiles;
  • approximately 1.4 million Family Tree profiles.

How did the attack develop?
The compromised accounts also exposed information shared by connected users. Following the incident, 23andMe required password resets and introduced mandatory two-step verification.

What could have reduced the impact?

  • unique passwords for every service;
  • mandatory MFA;
  • credential-stuffing detection;
  • limits on automated login attempts.

What do these incidents show?

At Uber, a valid password and one approved MFA request provided access to internal systems. At 23andMe, reused passwords enabled the takeover of thousands of accounts and exposed information linked to millions of profiles.

Both incidents show that valid credentials do not always mean legitimate access. Strong authentication, session controls, and monitoring for unusual login activity are essential for reducing account takeover risk.

Who they most often target

Credential abuse follows value.
Attackers go where credentials unlock scale, control, and persistence.

Roles
  • users with cloud, email, or VPN access

  • finance, HR, and operations teams

  • IT administrators and support staff

  • service and integration accounts

Sectors
  • professional services

  • healthcare and education

  • SaaS-heavy organizations

  • manufacturing and logistics

  • public sector

Organization types
  • heavily cloud-dependent

  • with remote and hybrid work models

  • lacking strong identity governance

  • with inconsistent access reviews

The more identity is central to operations, the more attractive it becomes.

What the attack relies on

Credential abuse rarely depends on a single failure.
It thrives where identity is trusted but not continuously verified.

Human factors
  • password reuse

  • phishing success

  • oversharing of credentials

  • MFA fatigue

  • social engineering follow-up

Technical gaps
  • missing or weak MFA

  • excessive standing privileges

  • shared or unmanaged accounts

  • limited identity telemetry

  • poor session visibility

Process weaknesses
  • weak onboarding/offboarding

  • rare access reviews

  • lack of identity incident playbooks

  • slow detection and response

Credential abuse succeeds when access outlives control.

How it is detected

Account takeover is rarely detected at login.
It is detected through behavior.

What users may notice
  • account lockouts

  • unexpected security prompts

  • unfamiliar sent emails

  • missing or altered data

What IT teams observe
  • new devices or locations

  • impossible travel patterns

  • abnormal session duration

  • privilege changes

What SOC teams detect
  • identity-based anomalies

  • token misuse

  • lateral movement

  • persistence mechanisms

When credentials are abused, identity becomes the primary telemetry source.

How impact is contained

Once credentials are abused, every minute increases attacker reach.

The first goal is to cut identity control.

  • force password resets and revoke sessions

  • disable compromised and related accounts

  • rotate tokens, keys, and service credentials

  • audit access paths and privileges

  • hunt for persistence and lateral movement

What does not help:

  • resetting only one account

  • assuming the compromise is isolated

  • delaying privilege review

Credential abuse spreads quietly. Containment must be decisive.

What realistically helps

Credential abuse is not prevented by perimeter tools.
It is managed through identity discipline.

People
  • training on credential hygiene

  • clear reporting paths

  • MFA awareness and response education

Processes
  • least privilege enforcement

  • regular access reviews

  • rapid deprovisioning

  • identity incident playbooks

Technology
  • MFA everywhere

  • identity threat detection

  • conditional access

  • session monitoring

  • XDR/SOC integration

The stronger the identity layer, the harder it is for attackers to operate unnoticed.

Regulatory context (EU)

With the enforcement of NIS2 and DORA across the EU in 2024–2025, credential abuse is no longer only a technical risk. It is a regulatory one.

Organizations in critical and important sectors are now explicitly required to:

  • maintain documented incident response playbooks, including identity-related incidents

  • demonstrate ability to detect, respond, and recover from account compromise

  • enforce access governance, MFA, and monitoring as part of compliance obligations

Credential incidents that are poorly handled are increasingly becoming not only security failures, but compliance failures.

Common myths

Credential abuse is often underestimated.

“Strong passwords are enough”
“MFA solves identity attacks”
“If someone logs in, it’s a real user”
“We would notice unusual access”

In reality, credential abuse remains one of the most persistent and damaging attack techniques across modern environments.


Attack #1: Phishing & Social Engineering

Next: Attack #3 – Business Email Compromise (BEC)

Could your email already be exposed? Use the DIAMATIX email exposure check to review whether your address appears in known breaches and understand what action may be needed. 

Subscribe for latest updates & insights

Please enable JavaScript in your browser to complete this form.