top of page

BeyondTrust Research Finds Identity and Privilege Exposure Behind 75% of Cyberattacks

  • 2 hours ago
  • 2 min read

An analysis of more than 400 offensive security projects shows attackers are increasingly exploiting connections between human users, machine identities, cloud services, and AI agents.


Identity security failures are emerging as the connective tissue behind modern cyberattacks, according to new research from BeyondTrust.


The company’s Phantom Labs Research Index found that identity or privilege exposure played a role in 75% of more than 400 offensive security investigations conducted during the past year. Rather than relying exclusively on previously unknown software flaws, attackers are increasingly abusing trusted access relationships that span cloud platforms, software-as-a-service applications, internal systems, and AI-powered tools.


Credential and secret exposure was the most common root cause, appearing in 18% of projects. Identity relationship exposure and excessive or standing privilege each accounted for 11%, followed by identity misconfiguration at 10% and lateral movement at 6%.


The findings suggest that enterprise risk often develops through combinations of weaknesses rather than a single security failure. Phantom Labs frequently observed standing privileges alongside privilege escalation, while exposed credentials were especially likely to amplify other vulnerabilities.


“As organizations connect human, machine, and AI agent identities across dispersed environments, attackers don't need to find a new vulnerability. They're looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today,” said Jonathan Johnson, senior manager of research at BeyondTrust.


AI Agents Expand the Identity Attack Surface


Artificial intelligence and large language model security represented half of Phantom Labs’ research projects, making it the team’s largest area of focus.


Researchers examined cloud AI platforms, autonomous agents, model and data security, prompt injection, jailbreak techniques, and AI-specific privilege escalation. The work highlights a growing enterprise security challenge: AI agents are beginning to function like employees or machine accounts, but may operate without equivalent identity governance.


These systems can authenticate to applications, call external tools, retrieve sensitive data, and inherit powerful permissions. A compromised or manipulated agent could therefore provide attackers with a new path to privileged access.


Phantom Labs also coordinated vulnerability disclosures involving OpenAI Codex and AWS Bedrock AgentCore. BeyondTrust said the findings demonstrate how emerging AI platforms can inherit longstanding weaknesses involving trust, access controls, and privilege management.


Across the full research dataset, AWS appeared most frequently, followed by Microsoft Entra ID and Azure, GitHub, Okta, and Salesforce. Their prominence reflects how identity relationships now extend across cloud infrastructure, development environments, identity providers, and business applications.


BeyondTrust said the research has already influenced its Identity Security Insights platform and broader security portfolio. The larger message for defenders is clear: securing individual accounts is no longer enough. Organizations must understand how identities connect, what access they inherit, and which relationships could become an attacker’s next path to privilege.

bottom of page