Identity reviews fail as entitlement sprawl fuels breaches

The gist

Identity governance is failing to stop breaches, as access reviews routinely leave dangerous permissions and credentials in place—even after the paperwork is done.

What to know

  • Sophos found identity-related root causes in 67% of 661 incident-response cases, with compromised credentials accounting for nearly half of breaches.
  • Routine access reviews often certify roles instead of actual permissions, letting old accounts and secrets linger where attackers can exploit them.
  • Incidents like 9,300 AWS keys left exposed in Hugging Face repos and Mirage 2FA bypassing MFA at 4,500+ orgs show how sprawl and weak enforcement fuel real-world attacks.

Workflows Mask Lingering Access

Identity governance often closes the books on access reviews without actually revoking permissions, leaving dormant accounts and entitlements for attackers to exploit long after employees depart.

The why-now failure is that governance programs are still being measured by completed workflows, not by whether authority actually disappears where access lives. As SC Media put it, “The quarterly certification closes with a 97% approval rate… Three months later, a departing employee's credentials are used in an intrusion,” because the revocation workflow closed without pushing changes to connected systems; that same pattern appears when reviews certify role assignments instead of effective permissions, or when owners cannot see what a labeled entitlement actually enables in downstream applications.

Recent identity incidents show how those structural gaps persist even when baseline controls look intact: Security Magazine argued that CISA’s 2026 awareness recommendations focus on baseline cyber hygiene but do not cover the identity-governance decisions needed to prevent credential misuse after compromise, leaving room for entitlement sprawl to persist. The analysis cites: “In a September 9, 2026, investigation, Microsoft’s Krithika Ramakrishnan and fellow researchers described intrusions involving unusual sign-ins followed by attacker-added authentication methods,” after which attackers collected cloud-hosted data—evidence that fragmented trust, enrollment, and enforcement decisions can validate access that governance should have stopped.

Sources

Visibility and Enforcement Breakdown

Fragmented permission models and weak integration keep reviewers in the dark, turning certifications into rubber stamps and letting risky entitlements persist unchecked.

The first structural weakness is visibility: governance systems often cannot normalize fragmented permission taxonomies or show owners what access actually means, so certifications become low-context exercises instead of control points. Software Analyst Cyber Research said reviewers are handed “raw, technical permissions” without business context, usage data, risk indicators, or peer comparison, producing “near-universal approval,” while fragmented entitlements across directories and apps force manual mapping that raises cost without creating durable visibility or consistent enforcement.

The next three weaknesses sit in execution: reviews stay role-centric because “over-complex role models” obscure effective permissions, lifecycle integration breaks after approval, and many tools stop at reporting or workflow creation rather than enforcement. Software Analyst Cyber Research explicitly says most IGA tools “were designed to orchestrate approvals,” so remediation “devolves into IT tickets” coordinated across “identity teams, app owners, and security staff”; its cited 2025 Identity Defined Security Alliance survey found 33% of organizations could not remediate identified identity risks quickly enough because of coordination and tooling limits.

Sources
Software Analyst Cyber Research

Identity Gaps Inflate Breach Impact

Weak identity controls are now the leading cause of costly breaches, with attackers routinely bypassing MFA and exploiting long-standing credential exposures across industries.

The exposure is not marginal; it is showing up as a dominant breach driver across real incidents. Sophos analysis of 661 incident response cases across 70 countries and 34 industries between November 2024 and October 2025 found identity-related root causes drove 67% of successful intrusions, while compromised credentials alone accounted for 42%; in the same dataset, MFA was absent or misconfigured in 59% of identity-related incidents, and even when MFA is correctly deployed, attackers adapted with adversary-in-the-middle proxies and infostealers that lift authenticated sessions. Paired with Cloudflare’s finding that 63% of logins involve credentials already compromised elsewhere and 94% of login attempts come from bots, the numbers show identity failure has become a primary attack path with direct financial consequences.

The cost side is just as concrete: CISO Talk pointed to 9,300 AWS credentials exposed in Hugging Face repositories, with 88% still active and some nearly two decades old, tying that persistence to missing rotation, inventory and governance. The same reporting said the Mirage 2FA platform was actively bypassing traditional MFA at more than 4,500 organizations by stealing authenticated sessions, and contrasted one case where common identity weaknesses were enough for complete domain and cloud compromise with another contained in under twenty minutes; even the headline “IRS Cybersecurity Program Was Not Effective for Fiscal Year 2026, Says Report” underscores that these are material, enterprise-scale risks.

Sources

Old Secrets, New Attack Paths

Retained credentials and stale admin keys allow adversaries—and even former insiders—to quietly inherit access and traverse networks, enabled by years of unchecked privilege sprawl.

Attackers do not need to smash through a perimeter when governance leaves valid identities and secrets behind. Cybersecurity Mastery showed how an ex-employee can keep operating after departure through retained access, guest accounts tied to a personal Gmail, shared admin passwords, service accounts, and copied cloud keys that “work from anywhere” and keep working until rotated; that risk is not hypothetical, as former cybersecurity professionals Ryan Goldberg and Kevin Martin pleaded guilty Thursday to participating in a series of ransomware attacks in 2023 while they were employed at cybersecurity companies tasked with defending clients. CyberWire Daily described the same end state more bluntly: adversaries are “gaining access through your legitimate users,” so if they get an administrator’s account, they inherit the environment instead of breaking in.

Once inside, the path through the estate is often already mapped by old privilege structures and reusable session artifacts. Palo Alto Networks warned that “Active directory has existed… for, you know, 20 plus years” and that “a lot of organizations don't do a good job of… saying… why does this group exist?”, while CISO Talk gave concrete examples of session abuse: “Mirage steals an already authenticated Microsoft 365 session” and “Information stealers go after browser cookies for exactly the same reason,” which is why it calls for “shorter session lifetimes, strong conditional access, rapid token revocation.”

Sources
Cybersecurity MasteryCyberWire DailyThreat Vector by Palo Alto NetworksCISO Talk by James Azar

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.