Hackers have abandoned traditional exploit tactics in favour of new technologies and techniques, allowing for faster, adaptive intrusions and highly targeted attacks, according to new research from Darktrace.
The cyber firm’s Annual Threat Report 2026 found that attackers have shifted toward credential abuse, with identity‑driven compromise now the dominant path into networks. Across the Americas, for example, nearly 70% of incidents began with stolen or misused accounts.
The study reveals that attackers are shifting from breaking through perimeter defences, like firewalls, to abusing trusted connections and permissions inside cloud‑based systems, targeting cloud entitlements, SaaS identity transitions, and supply-chain connectivity – fragile boundaries that rely heavily on identity to govern access.
Darktrace said that the findings are further evidence of a changing threat landscape reflected in real-world headlines across the past year, with high‑profile incidents at JLR, Marks & Spencer, and Salesforce demonstrating how quickly attackers can move once they gain access to legitimate accounts.
In each case, the breach did not begin with a sophisticated software exploit, but with a compromised identity. Once inside, attackers used trusted accounts and existing permissions to operate in plain sight, while legitimate tools disguised their malicious activity, accelerating impact while evading traditional controls.
The trend is reinforced by attackers’ growing focus on stealing high‑value identities. The report found more than 8.2 million phishing emails targeted VIPs in 2025, amounting to over a quarter of all phishing activity identified in that period.
Cloud compromise, in particular, has become the main entry point for cyber-attacks. Darktrace found that, across Europe, 58% of incidents began with compromised cloud accounts and email, overtaking traditional network breaches at 42%.
In the Americas, the study found attackers most often break in through SaaS applications and Microsoft 365 accounts, with many of these breaches escalating into double or even triple extortion campaigns.
“Traditional perimeter defences were built for a world where attackers had to break in; today, they simply log in,” said Nathaniel Jones, VP of security and AI strategy at Darktrace.
“Stopping identity‑led intrusions requires the ability to recognise when legitimate accounts begin to behave in ways that do not align with normal activity, and that means moving beyond static controls toward security that understands context and intent.”
Recommended reading
- Does Identity Security Have a “Post-Login” Problem?
- Comment | Identity, Not Surveillance, is Facial Recognition’s Future
- Identity Emerges As A Primary Attack Vector
While identity-based attacks have fast become hackers go-to tactic, Darktrace also discovered a level of innovation in the threat landscape that defenders are finding difficult to match.
For instance, analysis of 32 million phishing emails showed clear signs that AI‑assisted phishing is accelerating, with novel social engineering techniques rising from 32% to 38% and large‑text, long‑form messages increasing from 27% to 33%.
At the same time, QR‑code attacks are on the rise, with Darktrace detecting a 28% increase in QR code phishing attacks from 940,000 in 2024 to over 1.2 million in 2025.
Particularly worrying are new forms of QR phishing, including ‘splishing’, in which a QR code is split into two distinct images, and ‘nesting’, where a legitimate QR code is embedded with a malicious one, all designed to bypass link‑scanning tools and route victims through multi‑stage redirects.
Join the Conversation at ITSX Summit
How is customer service and IT support evolving in the age of AI, automation, and digital transformation?
Join us at the ITSX Summit in Edinburgh on 5th March, to unpack the future of ITSM, ESM, Self Service, and User Experience.
The event will bring together senior leaders from IT, Service Management, and UX, providing an ideal forum for shared learning, collaboration, and high-level networking.
Register now to secure your free place at ITSX Summit.





