Skip to content

Cybersecurity

Identity-Based Attacks: The Growing Cybersecurity Threat Every Business Should Understand

September 8, 2026 | ComputersDOTCalm

For years, cybersecurity focused heavily on protecting computers, servers, and networks. Today, attackers are increasingly targeting something much more valuable: identities.

An identity-based attack occurs when a cybercriminal attempts to gain access to a legitimate user account rather than directly attacking a device or network. Once an attacker successfully compromises an account, they can often move through systems unnoticed because they appear to be a legitimate user.

As organizations continue to adopt cloud services such as Microsoft 365, identity security has become one of the most important areas of cybersecurity.


What Is an Identity-Based Attack?

An identity-based attack focuses on obtaining or abusing authentication credentials such as:

  • Usernames
  • Passwords
  • Multi-Factor Authentication (MFA) approvals
  • Authentication tokens
  • Session cookies
  • Passkeys or authentication credentials

Instead of exploiting software vulnerabilities, attackers target the people and identities that have access to systems.

If successful, attackers may gain access to:

  • Email accounts
  • Microsoft 365
  • Financial systems
  • Cloud applications
  • Sensitive business data
  • Customer information

Why Identity Attacks Are Growing

Modern businesses rely heavily on cloud services.

Employees access company resources from:

  • Laptops
  • Smartphones
  • Home offices
  • Remote locations
  • Personal devices

This flexibility improves productivity but also creates more opportunities for attackers.

Because a valid account can provide access to multiple systems, identity attacks often offer attackers a faster path into an organization than traditional hacking methods.


Common Types of Identity-Based Attacks

Phishing

Phishing remains one of the most common identity attacks.

Attackers send convincing emails designed to trick users into:

  • Entering passwords
  • Revealing MFA codes
  • Clicking malicious links
  • Downloading malware

The goal is often to steal login credentials.


Password Spraying

Instead of targeting one account with many passwords, attackers attempt common passwords across many accounts.

Examples include:

Spring2026!

Password123

Welcome1

Even a single weak password can provide access.


Credential Stuffing

When passwords are leaked in previous breaches, attackers often try those same credentials against other services.

This attack is particularly successful when users reuse passwords across multiple websites.


MFA Fatigue Attacks

Attackers attempt repeated login requests hoping the user will eventually approve an MFA prompt by mistake.

Often referred to as:

  • MFA bombing
  • Push fatigue attacks

These attacks exploit human behavior rather than technical weaknesses.


Session Hijacking

After a user successfully signs in, websites create authenticated sessions.

Attackers may attempt to steal:

  • Browser cookies
  • Session tokens
  • Authentication tokens

This can sometimes allow access without requiring a password.


Business Email Compromise (BEC)

Business Email Compromise attacks occur when attackers gain access to legitimate email accounts and use those accounts to conduct fraud.

Examples include:

  • Fake invoice requests
  • Wire transfer fraud
  • Vendor payment changes
  • Executive impersonation

Because messages come from legitimate accounts, they are often difficult to detect.


Warning Signs of an Identity Attack

Organizations should watch for:

  • Unexpected MFA prompts
  • Login alerts from unfamiliar locations
  • Password reset notifications
  • Unusual email forwarding rules
  • Suspicious account lockouts
  • Unrecognized devices in account activity logs
  • Employees reporting strange login behavior

Rapid detection can dramatically reduce the impact of an incident.


How to Protect Your Business

1. Enable Multi-Factor Authentication Everywhere

MFA adds another layer of protection beyond passwords alone.

Even if a password is stolen, attackers still need a second authentication factor.

For most organizations, MFA should be considered mandatory.


2. Use Strong Unique Passwords

Never reuse passwords between:

  • Personal accounts
  • Work accounts
  • Banking websites
  • Cloud services

A password manager can help users maintain unique credentials for every account.


3. Consider Passkeys

Passkeys are emerging as one of the strongest forms of authentication.

Benefits include:

  • Phishing resistance
  • Improved security
  • Faster sign-ins
  • Reduced password dependency

Many major platforms, including Microsoft, are increasingly promoting passwordless authentication.


4. Implement Conditional Access Policies

Organizations using Microsoft 365 can leverage Conditional Access to:

  • Require MFA
  • Block risky sign-ins
  • Restrict access by location
  • Limit access from unmanaged devices

This significantly reduces identity-related risk.


5. Train Employees to Identify Phishing Attacks

Technology alone cannot stop every attack.

Employees should be trained to identify:

  • Suspicious emails
  • Unexpected login requests
  • Fake websites
  • Social engineering techniques

Security awareness training remains one of the most effective defensive measures.


6. Monitor Sign-In Activity

Regularly reviewing account activity can help identify:

  • Failed login attempts
  • Impossible travel scenarios
  • Unusual locations
  • Unauthorized device access

Early detection often prevents larger incidents.


7. Protect Administrative Accounts

Administrative accounts should receive additional security controls.

Best practices include:

  • Separate administrator accounts
  • MFA enforcement
  • Limited administrator privileges
  • Regular reviews of privileged access

Attackers frequently target administrative identities because they provide broader access.


Identity Security and Microsoft 365

Microsoft 365 environments are particularly attractive targets because they often contain:

  • Email
  • SharePoint
  • Teams
  • OneDrive
  • Company documents
  • Customer communications

A compromised Microsoft 365 account can quickly become a significant business issue.

Key Microsoft 365 security controls include:

  • MFA
  • Security Defaults
  • Conditional Access
  • Passkeys
  • Privileged Identity Management
  • Sign-in monitoring

Organizations that implement these controls dramatically improve their identity security posture.


The Future of Cybersecurity Is Identity-Centric

Modern cybersecurity is increasingly focused on protecting identities rather than simply protecting devices.

The traditional security perimeter no longer exists.

Today’s organizations must assume users will work from:

  • Home
  • Offices
  • Mobile devices
  • Cloud applications
  • Multiple locations

Strong identity protection has become one of the most important foundations of modern cybersecurity.


Final Thoughts

Cybercriminals understand that compromising a single account can provide access to large amounts of business information.

That is why identity-based attacks continue to grow.

The good news is that organizations can significantly reduce risk by implementing:

✅ Multi-Factor Authentication
✅ Strong password practices
✅ Passkeys
✅ Employee security awareness training
✅ Conditional Access policies
✅ Sign-in monitoring
✅ Administrative account protection

Identity security is no longer optional. It is one of the most important investments any organization can make.


Need Help Securing Microsoft 365 Identities?

ComputersDOTCalm helps businesses throughout Southwestern Ontario:

  • Deploy Multi-Factor Authentication
  • Configure Conditional Access
  • Implement passkeys
  • Secure Microsoft 365 environments
  • Reduce phishing risk
  • Improve identity security controls

Book a Free Microsoft 365 Security Assessment