Attack #2: Credential Abuse & Account Takeover
Threat snapshot – Credential Abuse & Account Takeover
| Category | Summary |
|---|---|
| What it is | Attacks where stolen or leaked credentials are used to access systems as legitimate users and move inside the environment without exploiting vulnerabilities. |
| Most common targets | Cloud services, VPNs, email platforms, admins, finance and operations teams, remote access infrastructure. |
| What it relies on | Stolen credentials, lack of MFA, excessive privileges, weak identity monitoring, and poor access hygiene. |
| How it’s detected | Abnormal logins, impossible travel, new devices, privilege changes, behavioral anomalies. |
| Primary impact | Persistent access, lateral movement, privilege escalation, data theft, ransomware staging. |
| What realistically helps | Strong identity security, MFA everywhere, least privilege, continuous monitoring, and fast containment playbooks. |
How the attack works
Credential abuse does not break systems. It uses them.
Once valid credentials are obtained. through phishing, malware, data leaks, or third-party breaches. attackers no longer need to “hack.” They log in.
From the outside, the activity looks legitimate. Correct usernames. Correct passwords. Often from realistic locations and devices. This is why credential abuse remains one of the hardest attack stages to detect.
Account takeover turns identity into the attack vector.
Real-World Cases
Credential abuse and account takeover attacks use valid passwords, sessions, or login approvals. This allows attackers to appear legitimate and bypass some standard security controls.
Uber (2022)
Sector: Technology and Transportation
How did the incident begin?
The attacker used a corporate password belonging to an external contractor, likely exposed after malware infected the contractor’s personal device. After repeated login attempts, the contractor approved one MFA (Multi-Factor Authentication) request.
What was compromised?
- employee accounts;
- internal tools, including Slack and Google Workspace;
- some internal messages and finance-related information.
How did the attack develop?
The attacker accessed additional employee accounts and gained elevated permissions. Uber blocked affected accounts, disabled some internal tools, and rotated access keys.
What could have reduced the impact?
- phishing-resistant MFA;
- protection against MFA fatigue;
- device and login-context verification;
- least-privilege access.
23andMe (2023)
Sector: Genetic and Consumer Services
How did the incident begin?
The attacker used credential stuffing — automated login attempts with usernames and passwords compromised elsewhere and reused on 23andMe. The company found no evidence that its own authentication systems had been breached.
What was compromised?
- approximately 14,000 accounts;
- around 5.5 million DNA Relatives profiles;
- approximately 1.4 million Family Tree profiles.
How did the attack develop?
The compromised accounts also exposed information shared by connected users. Following the incident, 23andMe required password resets and introduced mandatory two-step verification.
What could have reduced the impact?
- unique passwords for every service;
- mandatory MFA;
- credential-stuffing detection;
- limits on automated login attempts.
What do these incidents show?
At Uber, a valid password and one approved MFA request provided access to internal systems. At 23andMe, reused passwords enabled the takeover of thousands of accounts and exposed information linked to millions of profiles.
Both incidents show that valid credentials do not always mean legitimate access. Strong authentication, session controls, and monitoring for unusual login activity are essential for reducing account takeover risk.
Who they most often target
Credential abuse follows value.
Attackers go where credentials unlock scale, control, and persistence.
Roles
users with cloud, email, or VPN access
finance, HR, and operations teams
IT administrators and support staff
service and integration accounts
Sectors
professional services
healthcare and education
SaaS-heavy organizations
manufacturing and logistics
public sector
Organization types
heavily cloud-dependent
with remote and hybrid work models
lacking strong identity governance
with inconsistent access reviews
The more identity is central to operations, the more attractive it becomes.
What the attack relies on
Credential abuse rarely depends on a single failure.
It thrives where identity is trusted but not continuously verified.
Human factors
password reuse
phishing success
oversharing of credentials
MFA fatigue
social engineering follow-up
Technical gaps
missing or weak MFA
excessive standing privileges
shared or unmanaged accounts
limited identity telemetry
poor session visibility
Process weaknesses
weak onboarding/offboarding
rare access reviews
lack of identity incident playbooks
slow detection and response
Credential abuse succeeds when access outlives control.
How it is detected
Account takeover is rarely detected at login.
It is detected through behavior.
What users may notice
account lockouts
unexpected security prompts
unfamiliar sent emails
missing or altered data
What IT teams observe
new devices or locations
impossible travel patterns
abnormal session duration
privilege changes
What SOC teams detect
identity-based anomalies
token misuse
lateral movement
persistence mechanisms
When credentials are abused, identity becomes the primary telemetry source.
How impact is contained
Once credentials are abused, every minute increases attacker reach.
The first goal is to cut identity control.
force password resets and revoke sessions
disable compromised and related accounts
rotate tokens, keys, and service credentials
audit access paths and privileges
hunt for persistence and lateral movement
What does not help:
resetting only one account
assuming the compromise is isolated
delaying privilege review
Credential abuse spreads quietly. Containment must be decisive.
What realistically helps
Credential abuse is not prevented by perimeter tools.
It is managed through identity discipline.
People
training on credential hygiene
clear reporting paths
MFA awareness and response education
Processes
least privilege enforcement
regular access reviews
rapid deprovisioning
identity incident playbooks
Technology
MFA everywhere
identity threat detection
conditional access
session monitoring
XDR/SOC integration
The stronger the identity layer, the harder it is for attackers to operate unnoticed.
Regulatory context (EU)
With the enforcement of NIS2 and DORA across the EU in 2024–2025, credential abuse is no longer only a technical risk. It is a regulatory one.
Organizations in critical and important sectors are now explicitly required to:
maintain documented incident response playbooks, including identity-related incidents
demonstrate ability to detect, respond, and recover from account compromise
enforce access governance, MFA, and monitoring as part of compliance obligations
Credential incidents that are poorly handled are increasingly becoming not only security failures, but compliance failures.
Common myths
Credential abuse is often underestimated.
“Strong passwords are enough”
“MFA solves identity attacks”
“If someone logs in, it’s a real user”
“We would notice unusual access”
In reality, credential abuse remains one of the most persistent and damaging attack techniques across modern environments.
Attack #1: Phishing & Social Engineering
Next: Attack #3 – Business Email Compromise (BEC)






