For years, cybersecurity focused heavily on protecting computers, servers, and networks. Today, attackers are increasingly targeting something much more valuable: identities.
An identity-based attack occurs when a cybercriminal attempts to gain access to a legitimate user account rather than directly attacking a device or network. Once an attacker successfully compromises an account, they can often move through systems unnoticed because they appear to be a legitimate user.
As organizations continue to adopt cloud services such as Microsoft 365, identity security has become one of the most important areas of cybersecurity.
What Is an Identity-Based Attack?
An identity-based attack focuses on obtaining or abusing authentication credentials such as:
- Usernames
- Passwords
- Multi-Factor Authentication (MFA) approvals
- Authentication tokens
- Session cookies
- Passkeys or authentication credentials
Instead of exploiting software vulnerabilities, attackers target the people and identities that have access to systems.
If successful, attackers may gain access to:
- Email accounts
- Microsoft 365
- Financial systems
- Cloud applications
- Sensitive business data
- Customer information
Why Identity Attacks Are Growing
Modern businesses rely heavily on cloud services.
Employees access company resources from:
- Laptops
- Smartphones
- Home offices
- Remote locations
- Personal devices
This flexibility improves productivity but also creates more opportunities for attackers.
Because a valid account can provide access to multiple systems, identity attacks often offer attackers a faster path into an organization than traditional hacking methods.
Common Types of Identity-Based Attacks
Phishing
Phishing remains one of the most common identity attacks.
Attackers send convincing emails designed to trick users into:
- Entering passwords
- Revealing MFA codes
- Clicking malicious links
- Downloading malware
The goal is often to steal login credentials.
Password Spraying
Instead of targeting one account with many passwords, attackers attempt common passwords across many accounts.
Examples include:
Spring2026!
Password123
Welcome1
Even a single weak password can provide access.
Credential Stuffing
When passwords are leaked in previous breaches, attackers often try those same credentials against other services.
This attack is particularly successful when users reuse passwords across multiple websites.
MFA Fatigue Attacks
Attackers attempt repeated login requests hoping the user will eventually approve an MFA prompt by mistake.
Often referred to as:
- MFA bombing
- Push fatigue attacks
These attacks exploit human behavior rather than technical weaknesses.
Session Hijacking
After a user successfully signs in, websites create authenticated sessions.
Attackers may attempt to steal:
- Browser cookies
- Session tokens
- Authentication tokens
This can sometimes allow access without requiring a password.
Business Email Compromise (BEC)
Business Email Compromise attacks occur when attackers gain access to legitimate email accounts and use those accounts to conduct fraud.
Examples include:
- Fake invoice requests
- Wire transfer fraud
- Vendor payment changes
- Executive impersonation
Because messages come from legitimate accounts, they are often difficult to detect.
Warning Signs of an Identity Attack
Organizations should watch for:
- Unexpected MFA prompts
- Login alerts from unfamiliar locations
- Password reset notifications
- Unusual email forwarding rules
- Suspicious account lockouts
- Unrecognized devices in account activity logs
- Employees reporting strange login behavior
Rapid detection can dramatically reduce the impact of an incident.
How to Protect Your Business
1. Enable Multi-Factor Authentication Everywhere
MFA adds another layer of protection beyond passwords alone.
Even if a password is stolen, attackers still need a second authentication factor.
For most organizations, MFA should be considered mandatory.
2. Use Strong Unique Passwords
Never reuse passwords between:
- Personal accounts
- Work accounts
- Banking websites
- Cloud services
A password manager can help users maintain unique credentials for every account.
3. Consider Passkeys
Passkeys are emerging as one of the strongest forms of authentication.
Benefits include:
- Phishing resistance
- Improved security
- Faster sign-ins
- Reduced password dependency
Many major platforms, including Microsoft, are increasingly promoting passwordless authentication.
4. Implement Conditional Access Policies
Organizations using Microsoft 365 can leverage Conditional Access to:
- Require MFA
- Block risky sign-ins
- Restrict access by location
- Limit access from unmanaged devices
This significantly reduces identity-related risk.
5. Train Employees to Identify Phishing Attacks
Technology alone cannot stop every attack.
Employees should be trained to identify:
- Suspicious emails
- Unexpected login requests
- Fake websites
- Social engineering techniques
Security awareness training remains one of the most effective defensive measures.
6. Monitor Sign-In Activity
Regularly reviewing account activity can help identify:
- Failed login attempts
- Impossible travel scenarios
- Unusual locations
- Unauthorized device access
Early detection often prevents larger incidents.
7. Protect Administrative Accounts
Administrative accounts should receive additional security controls.
Best practices include:
- Separate administrator accounts
- MFA enforcement
- Limited administrator privileges
- Regular reviews of privileged access
Attackers frequently target administrative identities because they provide broader access.
Identity Security and Microsoft 365
Microsoft 365 environments are particularly attractive targets because they often contain:
- SharePoint
- Teams
- OneDrive
- Company documents
- Customer communications
A compromised Microsoft 365 account can quickly become a significant business issue.
Key Microsoft 365 security controls include:
- MFA
- Security Defaults
- Conditional Access
- Passkeys
- Privileged Identity Management
- Sign-in monitoring
Organizations that implement these controls dramatically improve their identity security posture.
The Future of Cybersecurity Is Identity-Centric
Modern cybersecurity is increasingly focused on protecting identities rather than simply protecting devices.
The traditional security perimeter no longer exists.
Today’s organizations must assume users will work from:
- Home
- Offices
- Mobile devices
- Cloud applications
- Multiple locations
Strong identity protection has become one of the most important foundations of modern cybersecurity.
Final Thoughts
Cybercriminals understand that compromising a single account can provide access to large amounts of business information.
That is why identity-based attacks continue to grow.
The good news is that organizations can significantly reduce risk by implementing:
✅ Multi-Factor Authentication
✅ Strong password practices
✅ Passkeys
✅ Employee security awareness training
✅ Conditional Access policies
✅ Sign-in monitoring
✅ Administrative account protection
Identity security is no longer optional. It is one of the most important investments any organization can make.
Need Help Securing Microsoft 365 Identities?
ComputersDOTCalm helps businesses throughout Southwestern Ontario:
- Deploy Multi-Factor Authentication
- Configure Conditional Access
- Implement passkeys
- Secure Microsoft 365 environments
- Reduce phishing risk
- Improve identity security controls