Half of All Real Attacks Now Target Logins, Says Prophet Security Review
A quarter of investigating every alert across customer environments shows identity abuse, help-desk trickery and old-school phishing still doing most of the damage.

Key points
- Prophet Security reviewed every confirmed malicious alert across its customer base from May to July 2026 and found identity attacks accounted for roughly half of all real incidents.
- The four dominant patterns were credential abuse, help-desk social engineering, phishing with adversary-in-the-middle kits, and misuse of legitimate remote-access tools.
- Attacks that bypassed multi-factor authentication almost always relied on session cookie theft rather than breaking the login itself.
- Fast human triage, not new tooling, was the single biggest factor in stopping attacks before data left the network.
A new review from Prophet Security, first reported by BleepingComputer, looked at every alert its analysts investigated for a full quarter and asked a simple question: when an attack actually worked, how did it work?
The answer, across May to July 2026, was not exotic. It was logins.
Roughly half of confirmed malicious activity in the dataset targeted identity: usernames, passwords, session tokens, and the humans who reset them. The rest split between phishing pages, abuse of trusted remote-access software, and social engineering aimed at IT help desks.
We would flag the usual caveat. This is one vendor's telemetry, weighted toward mid-market companies that already run a managed detection service. It is not the whole internet. But the patterns line up with what other incident-response shops have been quietly saying for a year.
What are the four attack patterns?
Prophet's analysts grouped the confirmed incidents into four buckets. Credential abuse came first: attackers logging in with valid usernames and passwords bought from criminal markets or scraped from earlier breaches. No malware, no exploit, just a working password.
Second was help-desk social engineering. Someone calls the IT help desk pretending to be an employee locked out of their account, and talks a support agent into resetting the password or enrolling a new phone for multi-factor authentication (the extra code or prompt after a password). This is the same technique tracked by Microsoft and others under the cluster Scattered Spider, though Prophet does not attribute the incidents it saw to any named group.
Third was phishing, where criminals send fake emails to trick staff into handing over passwords, but with a twist. The lures pointed to adversary-in-the-middle pages: fake login screens that quietly pass the victim's password and one-time code through to the real site, then steal the session cookie the real site hands back. That cookie lets the attacker skip the login entirely on their own machine.
Fourth was abuse of legitimate remote-access tools such as AnyDesk, ScreenConnect and Atera. Attackers install these instead of custom malware because security software rarely blocks them.
Why did multi-factor authentication not stop it?
Because the attackers usually did not try to beat it. They stole the session cookie after the user had already logged in, or they convinced a help-desk agent to enrol a new device on the victim's account.
Cookie theft in particular is a growing headache. Once an attacker has that cookie, the target's own security controls treat the intruder as the real user. Nothing lights up. This behaviour overlaps with tradecraft attributed to several financially motivated clusters, and the tooling is now sold as a service on criminal forums.
What worked in defence?
Here is the useful bit. The blocked attacks in Prophet's dataset shared a common trait: a human looked at the alert within minutes, not hours.
| Attack pattern | Share of confirmed incidents | Common defence that worked |
|---|---|---|
| Credential abuse | Largest single category | Blocking logins from unusual locations |
| Help-desk social engineering | Significant | Callback verification to a known number |
| Adversary-in-the-middle phishing | Significant | Phishing-resistant hardware keys |
| Remote-tool abuse | Smaller but growing | Allow-listing approved remote software |
Prophet's own pitch is that AI-assisted triage lets small security teams respond at that speed. Fair enough. The wider point stands on its own: the attacks winning right now are the ones that look like normal user behaviour, and they get caught by people who know what normal looks like on their own network.
What should ordinary staff take from this?
If your IT help desk calls you out of the blue to confirm a password reset you did not request, that is the attack. Say no, hang up, and call IT back on a number you already know.



