← Back to news 21.07.2026

The break-in that looks like a working day

For the first time in 19 years, stolen credentials are no longer the most common way into a network; exploited vulnerabilities have overtaken them. That sounds like relief for identity security, and it is not: across the full attack chain, credential abuse remains the most pervasive technique. Why a valid login raises no alarm, and only behavior gives it away.

This year's Verizon Data Breach Investigations Report made a headline: for the first time in 19 years, stolen credentials are no longer the most common way into a network. Exploited vulnerabilities have overtaken them, 31 percent against 13. That sounds like relief for everyone worried about identities. It is not.

Two numbers, two different questions

The first number describes the door. The second sits further back in the same report: across the entire attack chain, credential abuse appears in 39 percent of all incidents, more often than any other single technique. So the entry point has shifted, the path through the house has not. Whoever is inside continues with valid credentials: sideways, upwards, inconspicuously. That a break-in runs through a long-known vulnerability was covered here before. What happens inside afterwards is a problem of its own, and no patch helps against it.

A valid login looks like work

That is what makes this phase so uncomfortable: a stolen password raises no alarm. There is no exploit, no malware, no suspicious file. There is a correct sign-in with a valid account. Technically that is not an attack but a working day. What remains is behavior: a login at an hour when this account is never active. Two logins from places nobody could travel between in the time. The first access to a system this role has not opened in months. A deletion volume that falls outside the norm.

Behavior analytics your works council can support

That is what UEBA is for: it learns what is normal for an identity and reports what falls outside. In isidaten, dedicated detectors handle password spraying, impossible travel, unusual sign-in times, first-time resource access, mass deletions and volume outliers. There is a catch, though, that hardly any product video mentions: anyone evaluating employee behavior in Germany needs a legal basis and co-determination. That is why governance here is not an appendix but the main switch. The module stays locked until the legal basis is documented. A works-agreement profile defines which detectors may run at all. Analysts see pseudonyms instead of names, and every re-identification is logged. Behavior analytics becomes something the works council and the data protection officer can support.

More is shown on the UEBA module page. Where the evaluated events come from is covered by the SIEM integration.

Matching solution isidaten for ISO/IEC 27001

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.