Identity-Centric Threats: The New Reality
The cyberthreat landscape has transformed significantly with identity-based attacks emerging as a dominant threat vector. The 2025 Identity Threat Research Report, "Identity-Centric Threats: The New Reality," presents findings from research conducted by the eSentire Threat Response Unit (TRU) on shifting tactics, how they bypass traditional cybersecurity controls, and implications on organizational security posture. Download your complimentary copy of the report.
What are identity-centric threats?
Identity-centric threats refer to attacks that primarily target user identities and authentication mechanisms rather than exploiting technical vulnerabilities in systems. This shift has been driven by the realization that compromising user identities provides direct access to valuable organizational assets with less technical complexity. Recent data shows that identity-driven threats have increased by 156% between 2023 and 2025, now accounting for 59% of all confirmed threat cases.
How has Cybercrime-as-a-Service impacted identity theft?
Cybercrime-as-a-Service platforms have reshaped the landscape of identity theft by lowering the barrier to entry for threat actors. These platforms offer specialized services, such as Phishing-as-a-Service, which allow even those with limited technical skills to execute sophisticated identity theft campaigns. For example, platforms like Tycoon2FA, which can be rented for $200-300 per month, provide advanced credential harvesting capabilities, contributing to the increased frequency and sophistication of identity-centric attacks.
What measures can organizations take to combat identity threats?
Organizations should rethink their security posture by assuming that identities will be compromised. This includes implementing continuous authentication verification, comprehensive credential monitoring, and rapid response capabilities for identity-based threats. Regular threat hunting for unusual sign-ins, modifications to multi-factor authentication methods, and monitoring for suspicious email forwarding rules can also help mitigate risks associated with identity-centric attacks.
Identity-Centric Threats: The New Reality
published by Zakini Inc.
Like toddlers that play with iPads today, we were experimenting with technology back in the 80's as kids. Technology is in our DNA and we’ve seen the digital transformation from its inception to what it is today, a world created on the internet and driven by increasingly advanced technologies.
Our goal is to become leaders in helping the world transitioning the digital revolution. That is why, we currently help companies of all sizes to leverage the latest IT solutions, working securely from anywhere, across all devices. From IT infrastructure to cloud computing, our plans are flexible and cover a wide array of managed services: Microsoft 365, Cybersecurity, Voice Solutions, Networking, Video Surveillance, Smart Access Control, Virtual CIO and more.
Plan your IT strategy easily when you outsource your IT department with us and keep your costs under control avoiding surprises with flat rates and predictable expenses.
In case you haven’t heard of the word Zakini before, it sets our standards easy and straight to the point: Go forward. Move ahead. Be first.