4 MIN READ
Here is the part of the 2025 and 2026 breach postmortems that does not get quoted in the press release. No exploit was needed. One phished credential, one signed in endpoint, and a walk through the rest of the network like an employee who knew where the break room was. Snowflake, Okta, MGM, Caesars, all the same shape. The hard part of the modern breach sits as getting the first credential. Everything after that is the legitimate session doing legitimate things.
The pattern matters because it inverts how the security org should think about defence. The exploit needs a patch and a vulnerability. The legitimate credential needs a process change and a culture change, and the typical enterprise has neither. CISA, Mandiant, and the Verizon DBIR have all documented the same shift. The credential sits as the new perimeter, the password sits as the new vulnerability, and the SOC sits in the position of trying to spot an employee doing their job slightly differently than usual.
How the movement actually works
Initial access almost always starts with the same handful of methods. A phishing email that lands the user on a lookalike login page and captures the session cookie. A help desk call that walks through the MFA reset using stolen personal details. A password spray against the legacy VPN that nobody rotated. A push fatigue campaign that sends thirty prompts at 2am until the user taps “approve” to make it stop. Each one produces a real session on a real endpoint, with a real username in the logs.
From there, the path is slow. The same credential gets tried against the file share, the VPN, the email, the SaaS admin console, the backup appliance, anywhere the user has signed in before. The password reuse rate inside the typical org sits at 60 to 70 percent when you count minor variations like Spring2024 versus Spring2025, and they know this. The credential works. The user does not get a notification. The SIEM does not fire, because the SIEM does not alert on a user signing in from a device they have signed in from before.
The last move is privilege escalation through the shared service accounts. The contractor account that has read access to the S3 bucket. The break glass admin that three people share the password to. The CI runner that holds the deploy keys to production. The legitimate access, the shared secret, the high blast radius, all of it sitting in the same place they have already reached. The three phases together produce the lateral movement without the exploits, the lateral movement without the alerts, and the lateral movement without the SOC noticing until the data has already left.
Why the SOC misses it
Three failure modes stack on top of each other. The SIEM logs the legitimate session as normal activity and does not alert on the credential being used at 3am from a different continent. The analytics that look for a burst of failed logins or a spike in file access do not fire, because the pace is slow and the credential is being used the way the user would. The analytics that look for an unusual user do not fire either, because a real user has been stolen, with real privileges, signed in from a real device. The combination sits as the hardest attack pattern to detect and the easiest attack pattern to execute, and the asymmetry is what makes it dominant.
How to actually defend
Phishing resistant authentication removes the value of the initial phish. A passkey, a FIDO2 key, a conditional access policy that blocks legacy auth, any of them break the credential capture step. A user who cannot type their password into the fake site cannot be phished in the way the kit expects.
Network segmentation limits the blast radius. The endpoint that gets compromised can reach the next endpoint, not the production database. They are stuck pivoting rather than exfiltrating, and the time they spend pivoting sits as the time the SOC has to notice.
Impossible travel analytics catch the credential reuse. The same user signing in from London at 9am and from São Paulo at 9:14am is not the same person, and the alert that fires on that pattern is the alert that catches the stolen session before the data leaves. The org that runs those three sits as the one that defends against the lateral movement without the exploits.

The bottom line
Phishing resistant authentication, network segmentation, impossible travel analytics. The org that runs those three holds the line. The one that still relies on the push notification and the flat network loses it.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.



