Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer

Compromised credentials remain the cheapest entry point on criminal marketplaces. A new webinar argues behavioral models, not static rules, are the only way to close the gap.

ThreatVectr Newsdesk· 2 min read
Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer
Share

Account takeover is the workhorse of the criminal economy. Initial access brokers sell credentials for as little as $10 a set on Russian-language forums, and ransomware affiliates buy them by the bundle. The attack does not require malware. It requires a working password.

That is the problem a forthcoming industry webinar is pitching to solve, and it is worth examining the argument on its merits.

The pitch: behavioral AI, applied to identity telemetry, can flag a logged-in session as hostile even when the credentials, the device fingerprint, and the MFA token all check out. Static rules cannot. Conditional access policies built around geography and device posture are routinely bypassed by attackers using residential proxies and session-cookie theft.

The operational case is hard to argue with. Scattered Spider, the loose collective tied to the MGM and Caesars intrusions in 2023, ran almost entirely on social-engineered account takeovers. Caesars reportedly paid roughly $15 million. MGM refused and absorbed an estimated $100 million in losses. Neither incident began with an exploit. Both began with a help desk and a phone call.

The broader pattern holds across the ransomware ecosystem. LockBit affiliates, before the February 2024 NCA-led takedown, leaned heavily on valid accounts purchased from brokers. ALPHV/BlackCat operated the same way. Cl0p's MOVEit campaign was the outlier, not the norm.

What behavioral systems claim to catch is the after-login drift. Unusual mailbox rule creation. OAuth grants to obscure third-party apps. Sudden interest in finance shared drives from an engineering account. The MITRE ATT&CK framework catalogs these as T1078 - Valid Accounts and the related persistence techniques, and they are the techniques defenders consistently rate hardest to detect.

The skeptical read is that "behavioral AI" has been a vendor slogan for a decade. Anomaly detection generates alerts. Alerts generate fatigue. Fatigue generates ignored alerts. Whether the current generation of large-model-assisted tooling actually moves the needle on mean-time-to-detect for ATO is an open empirical question, and most published numbers come from the vendors themselves.

What is not in dispute is the demand side. Microsoft's most recent Digital Defense Report put identity-based attacks at more than 600 million per day across its tenants. CISA's advisories on Midnight Blizzard and Storm-0558 both centered on token theft and account abuse rather than novel exploits.

The webinar audience, in other words, has a real problem. Whether the proposed answer is the right one is a separate question, and one buyers should put to vendors directly: show the false-positive rate, show the dwell-time delta, show the customer who refused to pay because detection fired in time.

Anything short of that is marketing.

© 2026 Threat Vectr