Table of Contents
How vulnerability exploitation took the initial access vector lead
Don't have the time to read the entire post? Our human writers will be sad, but we understand. Summarize the post with your preferred LLM here instead.
Our analysis of the Verizon 2025 Data Breach Investigations Report led with a simple fact: credentials were still the number one threat. The biggest surprise in the Verizon 2026 Data Breach Investigations Report (DBIR) was seeing the exploitation of vulnerabilities become the most common initial access vector, kicking off 31% of all breaches. Credential abuse fell to 13%.
![Fig: Known initial access vectors in non-Error, non-Misuse breaches over time (n for 2026 dataset=19.905) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F4O6dKXPjjl0b8rrlWLoJ6W%2F2493b4029c872faffdfc287d6fef8e3a%2FKnown_initial_access_vectors_in_non-Error__non-Misuse_breaches_over_time__1_.png&w=3840&q=75)
Reading past the headline shakeup, and it becomes clear that the status quo isn’t completely inverted. When credential abuse is counted at any point in the breach progression (rather than only the first step), it’s still on top at 39%. The story-behind-the-story here is that attackers have changed where they break in, but they haven’t changed what they reach for once inside.
In this analysis, we’ll unpack findings from the Verizon 2026 Data Breach Investigations Report and explore what they mean for organizations managing customer, partner, and agentic identities.
Main points
Credentials are still the chokepoint: Credential abuse lost the top initial access vector mostly on a methodology change; it still appears at some point in 39% of breaches. Passwords are partly to blame, with users four times more likely to use an already-compromised one than a weak new one.
Third-party breaches are identity failures: Third-party involvement grew by 60% year over year to touch 48% of breaches, and the report traces most headline-making incidents back to absent multi-factor authentication (MFA), poor credential rotation, or missing least privilege.
Shadow AI points to the agent identity problem: 45% of employees now use AI regularly on corporate devices, two-thirds through personal accounts; AI-driven traffic grew 21% month over month against flat human traffic.
How vulnerability exploitation took the initial access vector lead
Exploitation of vulnerabilities reached 31% of breaches as the first known initial access vector, up 55% from 2025’s 20%. Credential abuse dropped from 22% to 13% over the same period.
![Fig: Initial access vectors—select enumerations in non-Error, non-Misuse breaches (n=20,023) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F5bq2NIOiQBYBGSArzyqbJV%2F008e87c0b71f4a6a60f4b02651a2ff5f%2F3ab18ed8-680c-4d84-9fdc-ae8a0d842f9c.png&w=1920&q=75)
Verizon offers two caveats up front to address this change:
The drop is partly methodological. This year’s report added pretexting to its tracked initial access vectors, and because pretexting incidents frequently involve credential abuse, the new category absorbed part of credential abuse’s share. Measured like last year, credential abuse would’ve landed at 16% (admittedly, still only half that of vulnerability exploits).
Initial access is only the first step. When counting credential abuse anywhere in the attack progression, the DBIR finds it in 39% of breaches. That’s more than any other vector, and Verizon warns not to discount it.
![Fig: Select initial access vectors in non-Error, non-Misuse breaches over time (n for 2026 dataset=19,905) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F7dxJUMUyFMhKDaaS6dH9lG%2F2fc6d81641b0fc059c2e1f6e79045a07%2FSelect_initial_access_vectors_in_non-Error__non-Misuse_breaches_over_time__1_.png&w=3840&q=75)
But methodology alone doesn’t explain such a dramatic shift, so why did vulnerabilities take the lead for the initial access vector? It’s certainly not because credentials got harder to steal. Instead, it seems that responses to security gaps deteriorated, and remediation (patching vulnerabilities) got much worse.
![Fig: CISA KEVs per CVE resolution status (n=515,170) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F4wiJYHfrv55UoMqLQOLHMA%2Faaf38b91446bb709bf3a00b7efa55a69%2FCISA_KEVs_per_CVE_resolution_status__1_.png&w=1920&q=75)
Only 26% of critical vulnerabilities, defined by inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog, were fully remediated. The median time to full remediation rose to 43 days, and organizations had roughly 50% more critical vulnerabilities to remediate than the previous year. The story here isn’t particularly novel: attackers go where the resistance is weakest at scale, and right now, that looks to be the patch backlog.
Which is worse: a weak password, or a compromised one?
Password complexity is a solved problem. The median share of Active Directory passwords failing minimum complexity requirements was under 1%. However, the share of users running passwords that already appear in breach data was 4%, meaning users are more than four times as likely to use a compromised password as a weak one. Meanwhile, a median of 6% of users reuse passwords or hold the same password as other users.
![Fig: Distribution of percentage of accounts scanned with breached passwords (n=7,345) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F4q5nHwtXi9pErmY7pGDuNI%2F469953dae43a02fb928b7ccdd09c815d%2FDistribution_of_percentage_of_accounts_scanned_with_breached_passwords__1_.png&w=3840&q=75)
As we discussed in our previous DBIR analysis, the circulation of credentials is its own microeconomy. In the latest report, credentials appeared as compromised data in 28% of breaches. Stolen credentials remain the top action in the Basic Web Application Attacks pattern, and credentials are 52% of the data compromised as a result.
Just as in the previous year, infostealers are key enablers for credential-based attacks. Ransomware appeared in 48% of breaches investigated by the 2026 DBIR, and most ransomware victims (73%) had an associated infostealer or credential leak within the year. Among those that did, half (50%) saw the leak within 95 days prior to the ransomware attack. Small organizations faced a median of seven credential leak events over the year, while large organizations saw around 20.
![Fig: Distribution of days where a credential leakage event occurred prior to ransomware (n=4,395) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F4vhL3uHNiem3gmrYcEAgO9%2Fb10a06ac76282516a272999bed7a1b16%2FDistribution_of_days_where_a_credential_leakage_event_occurred_prior_to_ransomware__1_.png&w=3840&q=75)
Our State of Customer Identity research found that 87% of organizations still run password-based auth for customer-facing apps, while only 2% consider it the most effective method. Dashlane puts the average number of managed passwords per person at 301, which is an enormous attack surface. Passkeys are the simplest solution: credentials that never leave the user’s device, can’t be used on spoofed sites, and have zero resale value even if they could be held by someone other than the owner.
Adoption has caught up to this argument slightly more over the last year. FIDO’s State of Passkeys 2026 estimates 5 billion passkeys are in use worldwide, with 90% of consumers at least aware of passkeys and 75% enabling passkeys on at least one account. The counterpoint is that 57% of organizations that deployed passkeys still rely on phishable methods (like passwords) as their primary sign-in.
Why third-party breaches are your identity failures, too
A couple of reports prior to the Verizon 2026 DBIR, third-party involvement sat at 15% of breaches. In 2025, it doubled to 30%. And this year, it grew to 48%, a 60% increase. The trend doesn’t need embellishment; it’s climbing steadily, year over year.
![Fig: Select key enumerations in breaches [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F5iH1OJeohlfL77aLskVbMy%2F74029b7ea273e22e4dc8e53d73ad61d4%2FSelect_key_enumerations_in_breaches__1_.png&w=1920&q=75)
The archetypal third-party breach case, which Verizon draws directly from publicly disclosed information, is the campaign against the Salesloft Drift application. In this attack pattern, stolen customer OAuth tokens were used against the Salesforce platform to exfiltrate customer data.
Here’s the root-cause analysis the DBIR lays out for this and other headline incidents: insecure authentication (like absent MFA or improper credential rotation) and ineffective authorization (like missing least privilege for users and service accounts).
The remediation numbers show just how slowly these causal issues get fixed:
23% of third-party organizations fully remediated missing or improperly secured MFA on their cloud accounts
Weak passwords and permission misconfigurations took nearly eight months to reach 50% resolution, and full remediation topped out at 31%
37% of organizations had an admin account with MFA disabled on an infrastructure-as-a-service (IaaS) offering
On Snowflake, the figure was 14%, which Verizon reads as a marked improvement over last year; however, Snowflake has been forcibly phasing out single-factor sign-ins since late 2024, yet one in seven accounts stayed exposed anyway
![Fig: Survival analysis of third-party, cloud-based MFA exposures (n=7,513) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F5yIuZpEkQfJUKpTNz3LlRB%2Fb862804b58157c1a92d25a3b2e5e6267%2FSurvival_analysis_of_third-party__cloud-based_MFA_exposures.png&w=3840&q=75)
In most cases, you can’t patch a partner organization. Their MFA rollout, password hygiene, and permission sprawl all sit outside your control. In a B2B2X scenario, where your business serves other businesses and every end customer beyond them, their authentication posture is often your attack surface.
What you can actually control is what their access is capable of. Proper tenant isolation, with per-tenant configurations, and self-service single sign-on (SSO) with SCIM instead of long-lived, hand-configured setups. Pair that with scoped OAuth tokens that have proper expiry and revocation, and a stolen token dies on schedule or on demand (instead of surviving for months after a breach).
Is shadow AI a preview of tomorrow’s agentic identity problems?
The share of employees who are regular AI users on corporate devices tripled in a year, from 15 to 45%. The governance numbers, however, did not keep up:
67% of that AI access flows through personal, non-corporate accounts
Shadow AI is now the third most common non-malicious insider action in the report’s data loss prevention dataset, increasing four times over the last year
The most common data type submitted to external GenAI tools is source code
![Fig: Select data types in untrusted DLP events targeting generative AI tools (n=858,440) [Source: Verizon 2026 Data Breach Investigations Report]](/_next/image?url=https%3A%2F%2Fimages.ctfassets.net%2Fxqb1f63q68s1%2F2Ow4PZo9C4uMD5ZSeLa6hX%2F9b08adb3c6ba0046bc0187f5c6226073%2FSelect_data_types_in_untrusted_DLP_events_targeting_generative_AI_tools__1_.png&w=3840&q=75)
Employees aren’t intentionally sidestepping security policies because they’re careless, though. It’s often because an official path doesn’t exist in the first place. So, their AI use runs on accounts the organization can’t see, with unscoped access and unauditable activity.
On the wider stage, traffic patterns are shifting. AI bot traffic grew 21% month over month across observed industries while human traffic remained flat. The median visitor to your application trends non-human, and combined with employee shadow AI use, it’s hopefully a wake-up call that ungoverned agent access at scale needs to be addressed.
Our State of Customer Identity research found that 46% of organizations say their engineering teams lack the time or expertise to build and manage agentic identity properly.
Meanwhile, the latest Stack Overflow Developer Survey points in the same direction from the builder side: 84% of developers use or plan to use AI tools, but security or privacy concerns are the top reason they’ll abandon a technology. That’s probably why a majority of the developers surveyed (52%) don’t use agents, and a hefty portion (38%) have no plans to.
Ultimately, the demand for governed AI access exists on both sides of the equation. The systems to make it secure exist, too, but organizations simply aren’t ready or able to put them into practice on their own.
Learning from DBIR data to build better auth
At its core, the 2026 DBIR supports several moves that security and identity teams can make now, and some they can plan to make in the future.
Right now, you should:
Enforce password policy based on NIST guidelines (e.g., don’t arbitrarily reset credentials)
Screen passwords against data breaches at signup and login, such as with Descope’s Have I Been Pwned connector
Add MFA everywhere it’s absent, especially admin accounts and ones your vendors and partners hold
Put an intentional lifecycle on every OAuth token with scopes, expiry, and revocation
In the future, plan to:
Step up to MFA when risk signals fire, or for sensitive interactions
Use stronger MFA methods, like authenticator apps and magic links as a second factor
Stop using shared secrets that can be compromised at all by switching to passkeys
Give AI agents auditable first-class identities with authentication, consent, and scoped access
Descope makes all of these moves a drag-and-drop exercise rather than a rebuild, from common use cases like passwordless authentication and adaptive MFA, to emerging auth challenges like agentic identity.
Ready to put this year’s DBIR findings into practice? Sign up for a Free Forever Descope account and start mapping identity flows with drag-and-drop simplicity. Join AuthTown, our developer community, to compare notes with other builders. And try passkeys firsthand with our interactive demo at passkeys.guru.
You can also book time with our experts to talk through all things auth, like how the Agentic Identity Hub can help you secure AI agents.


