BeyondTrust Report Highlights Rise of Identity-Based Cyberattacks

0
BeyondTrust has released its Phantom Labs® Research Index, an annual report examining the tactics driving today’s cyberattacks based on the company’s offensive security research. The findings reveal that attackers are increasingly targeting trusted relationships between users, applications, machine identities, and AI agents, rather than relying solely on exploiting software vulnerabilities, highlighting the need for identity-centric security strategies.

Analyzing more than 400 research projects over the past year, Phantom Labs found that 75% of completed investigations involved identity or privilege in some way.

Sorted by root cause, six problems accounted for more than half of everything the team found: credential and secret exposure (18%), identity relationships and graph exposure (11%), excessive or standing privilege (11%), identity misconfiguration (10%), and lateral movement (6%). These root causes rarely appeared in isolation. Standing privilege and privilege escalation showed up together most often, and credential exposure was the issue most likely to compound with something else.

“As organizations connect human, machine, and AI agent identities across dispersed environments, attackers don’t need to find a new vulnerability. They’re looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today,” says Jonathan Johnson, Sr Manager, Research at BeyondTrust“That’s exactly what we saw across our research this year: three out of four projects traced back to identity or privilege in some form, and standing privilege and privilege escalation showed up together more often than any other combination we tracked.”

AI Agents Are Becoming Enterprise Identities

AI and LLM security was Phantom Labs’ single largest research focus in year one, accounting for half of all projects. That work spanned cloud AI platforms (58%), AI agents and agentic systems (42%), model and data security (12%), prompt injection and jailbreak techniques (9%), and AI-specific privilege escalation (6%), with many projects touching more than one category. 

As organizations deploy AI agents across cloud, SaaS, and internal workflows, BeyondTrust found that these agents increasingly authenticate to systems, invoke tools, access data, and inherit permissions much like any other enterprise identity – often with far less oversight.

Coordinated Disclosures in OpenAI Codex, AWS Bedrock AgentCore Show the Pattern Isn’t New

Beyond identity relationship mapping, Phantom Labs’ original vulnerability research included coordinated disclosures across AI platforms, including in OpenAI Codex and AWS Bedrock AgentCore — findings that show how even the newest AI ecosystems continue to inherit foundational security assumptions around identity, privilege, and trust. The pattern wasn’t confined to AI.

Across all research conducted in year one, AWS (85 mentions), Microsoft Entra ID/Azure (57), GitHub (40), Okta (33), and Salesforce (33) surfaced most often — a sign that these same identity assumptions run through cloud, identity-provider, DevOps, and SaaS ecosystems alike.

Phantom Labs’ research shipped directly into BeyondTrust products, including Identity Security Insights®, published research, and coordinated disclosures, turning the offensive research into protections defenders can act on before privileges are exploited.

To read the full Phantom Labs Research Index, visit: https://www.beyondtrust.com/blog/entry/phantom-labs-research-index or https://www.beyondtrust.com/

Related News:

BeyondTrust Launches NHI Governance for Non-Human and AI Identities

State of Agentic AI Adoption: Volume ll Report Released by Snyk

Share.

About Author

Leigh Porter's first love is to love people. Beginning her career as a neonatal RN was an obvious choice until life threw the curve ball to embark on a new IT endeavor. Pursuing this fresh career was a piece of cake with her resilient and steadfast character. Outside of the office, Leigh also diligently gives much of her time faithfully as a nationally awarded volunteer leader to a very dear to her heart organization.