Perspectives

Cybersecurity Awareness Month 2026: How Identity Attacks Get In

Most breaches are told in vocabulary nobody defines. A Cybersecurity Awareness Month 2026 guide to the nine identity attack vectors, the terms behind them, and what breach letters leave out.

Published: By Andre Arantes6 min read--:--
Illustrated aged-parchment map spread across a wooden table while a service-desk agent in a headset, a security lead and an analyst trace routes with their fingers. Dotted lines converge on a walled keep marked with a person icon at the center: blue routes run from a mapped office campus, red routes creep in from shaded hazard regions at the edges, and green guards stand at the gates.
TL;DR~40s read · skim-friendly summary

Most breaches are told in vocabulary nobody defines. A Cybersecurity Awareness Month 2026 guide to the nine identity attack vectors, the terms behind them, and what breach letters leave out.

  • Cybersecurity Awareness Month 2026 is a good moment to fix a vocabulary problem: breach reporting uses terms like vishing, MFA fatigue and orphaned account without ever defining them, so teams can't tell which control failed.
  • Avatier's attackcost.com maps nine identity attack vectors, defines 41 terms, most of them grouped under those vectors, and profiles eight threat actors, each included because a US government advisory, charging document or sanctions designation names it.
  • Smishing, vishing and quishing are one lure in three wrappers. The glossary's fixes pair up: phishing-resistant MFA for the text and QR versions, caller verification for the phone version.
  • In California breach filings, only 6.7% of readable letters filed 1 January to 14 August 2026 name a vector, and five identity vectors appear zero times across 2,161 filings from 1 January 2023 to 14 August 2026.
  • Zero in breach letters means undisclosed, not rare. Session theft, dormant accounts, standing privilege, machine identities and federation compromise still need controls, whatever public filings say.

For identity teams, Cybersecurity Awareness Month 2026 should be about learning how attackers actually get in. attackcost.com sorts identity attacks into nine routes, from phished or stolen credentials and social engineering of a person to orphaned or dormant accounts and session or token theft. That matters because breach coverage is full of words like vishing, MFA fatigue and orphaned account, and almost nobody defines them. So a team reads that an attacker "gained access through social engineering" and can't say which control failed. Avatier publishes a free set of resources for exactly that on attackcost.com: nine attack vectors, a 41-term glossary, eight threat-actor profiles sourced to US government documents, and a ledger of California breach filings. This post uses them as a map.

The nine vectors are the map

The attack vectors page sorts identity attacks into nine routes. Four are routes that California breach letters actually name: phished or stolen credentials, social engineering of a person, third-party or contractor access, and MFA bypass. The other five never appear in those letters: session or token theft, orphaned or dormant accounts, over-provisioned standing access, service-account or non-human identity abuse, and SSO, IdP or federation compromise.

Each vector links to the glossary terms that describe how it is done, the threat actors US authorities tie to it, and what filed breach letters say about it. When an incident report uses a term, you can trace it back to a route and then to the control that guards that route.

Aged-parchment map titled "Nine ways in through identity" with a walled keep labeled Identity at the center. Four blue territories on the left, under "Named in California breach letters", and five red hazard territories on the right, under "Never named in those letters", each send a dotted route to the keep. Footer: name the route first, then check the control that guards it. Nine routes into one identity. Name the route first, then check the control that guards it before the next incident uses it.

Three ways in, worked through the glossary

The 41-term glossary gives each term a plain definition, a sourced example and a way to stop it.

One lure, three wrappers. Smishing is phishing by text message, usually pushing the reader toward a fake login or payment page. Vishing is the same play by phone: callers pose as IT support or a locked-out employee, and at a help desk the goal is often a password reset or a new MFA device on the attacker's phone. Quishing hides the link in a QR code, which can slip past email filters that inspect written URLs and opens the fake page on a personal phone. The glossary's fixes pair up: phishing-resistant MFA for the text and QR versions, caller verification for the phone version. Phishing-resistant MFA bound to the real site keeps a captured password from being enough, and help-desk callers get verified with something an attacker cannot look up. Our quishing guide goes deeper on the QR channel.

Aged-parchment map titled "One lure, three wrappers." Red dotted routes from Smishing and Quishing reach a red town drawn as a fake login page, stopped by a green fort labeled phishing-resistant MFA bound to the real site. A route from Vishing reaches a red help-desk town, stopped by a green caller-verification watchtower. Both lead on to a blue castle labeled Real account. Text, voice and QR code are three wrappers on one lure. Two controls cover them: phishing-resistant MFA at sign-in and caller verification at the help desk.

MFA fatigue. This one floods a user with push prompts until a tired tap approves one. The attacker already has the password. Citing public reporting, the CISA and FBI advisory on Scattered Spider says the group's actors sent repeated MFA prompts that led employees to press Accept. The glossary recommends phishing-resistant MFA, or at least number matching with sign-in context, plus prompt limits and alerts on bursts of denied pushes. See MFA fatigue defense patterns for rollout detail.

Orphaned accounts. An orphaned account has no valid owner, usually because the person left or the system was retired, yet it stays active. In a February 2024 advisory, CISA and MS-ISAC said a state government organization found that documents posted on a dark web brokerage site had been accessed through the compromised account of a former employee. The glossary's fixes are administrative: give every account a named owner, tie removal to HR departure records across all systems, and run regular reconciliations that disable any account without a current owner.

What breach letters say, and what they never say

The Identity Attack Ledger reads every breach notification filed with the California Attorney General from 1 January 2023 to 14 August 2026, which comes to 2,161 filings. Letters aren't required to say how the attacker got in, and most don't. Of readable letters filed between 1 January and 14 August 2026, 6.7% name a vector, up from 1.5% of readable 2023 letters.

Across the corpus, 53 distinct incidents name a vector: 31 cite phished or stolen credentials, 12 social engineering of a person, 9 third-party or contractor access, and 1 MFA bypass. The other five vectors appear zero times in the ledger's 2,161 California filings. That zero is a finding about disclosure practice, not about attacker behavior. Session theft, dormant accounts, standing privilege, machine identities and federation compromise are well documented in incident-response reporting. They just don't survive into a consumer notification letter.

Aged-parchment chart titled "What California breach letters name", subtitled 2,161 California AG filings, January 1, 2023 to August 14, 2026. Blue charted land on the left shows 53 named incidents as green routes: credentials 31, social engineering 12, third-party 9, MFA bypass 1. Red terra incognita on the right shows the five vectors named zero times. Footer: zero means undisclosed, not rare. Four vectors get named in California filings and five never do. Treat that zero as a blind spot in disclosure, not as proof the risk is low.

Across 2,030 filings from 1 January 2023 to 14 August 2026 with both dates stated, the median from breach start to filing is 157 days. That is not time spent undetected: the clock includes the undetected period, the investigation, legal review and notification, most of it after the organization already knew. Where a letter gives the first and last day of access, the attacker's own window runs to a median of 7 days.

The groups behind it, as government advisories describe them

The threat-actors page lists eight groups alphabetically, not ranked, each included because a US government advisory, charging document or sanctions designation names it. Three show how the vectors connect:

  • Scattered Spider. A joint FBI and CISA advisory describes a cybercriminal group that targets large companies and their contracted IT help desks. Citing public reporting, its July 2025 update says the actors posed as employees to get help-desk staff to reset passwords and move MFA to devices they controlled.
  • APT29. The UK NCSC and international partners assess that it is almost certainly part of Russia's SVR, and NSA, CISA and the FBI agree. A February 2024 advisory (CISA AA24-057A) says SVR campaigns targeted dormant accounts of users who no longer worked at the victim organization.
  • Volt Typhoon. CISA, NSA and the FBI describe a PRC state-sponsored group that relies on valid accounts and living-off-the-land techniques.

Dormant accounts are one of the five vectors that never appear in California breach letters.

A one-week Awareness Month checklist

  1. Monday: teach the map. Walk the service desk and IT through the nine vectors, then have each team name the control that covers each route.
  2. Tuesday: run a channel drill. Send a simulated text, call and QR lure that all point to the same page, and measure reports, not just clicks.
  3. Wednesday: test help-desk verification. Can an agent verify a caller without information an attacker could look up?
  4. Thursday: check push settings. Confirm number matching, prompt limits and alerts on bursts of denied pushes. Our MFA bypass guide covers the factor side.
  5. Friday: sweep the zeros. Pull accounts with no owner or no recent sign-in, and service accounts nobody can explain.

What Avatier ships toward this pattern

The Identity Challenge Card is a printed grid card for phone-free verification. It gives workers a way to prove who they are to the help desk without a smartphone, an SMS code or answers an attacker could research, which supports the caller-verification control the glossary recommends against vishing. It works alongside phishing-resistant MFA for everyday sign-in rather than replacing it. The card is part of the Identity Anywhere 2027 platform from Avatier, and Credential Governance covers the password and reset side. Our compliance posture is published on the Avatier Trust Center.

What awareness alone does not solve

Training helps people notice smishing, vishing and quishing. It does nothing for the five vectors that never appear in the ledger's 2,161 California filings. Nobody can be trained to spot a replayed session cookie or a service key sitting in a script. An account a former employee left behind needs an owner and lifecycle automation that switches it off. Standing access needs trimming back to least privilege, and that work doesn't end with the month.

About the author

Andre Arantes
Andre Arantes

Andre Arantes is an AI Security Engineer at Avatier focused on authentication architecture, FIDO2 and passkey deployment, and the operational reality of preventing credential compromise across enterprise environments.

Recognized on Gartner Peer Insights

4.4

Based on 14 verified reviews of AvatierIdentity Governance and Administration

Read the reviews on Gartner Peer Insights