The Top 4 Threats We Found by Investigating Every Alert for a Quarter

**Attackers Focus on Identity Theft in 93% of Malicious Activity**

Cybersecurity firm Prophet Security has released its quarterly threat report, revealing disturbing trends in malicious activity from May to July 2026. The company investigated every alert in customer environments during this period and found that identity theft was the target in roughly half of all confirmed malicious activity.

This means that cyber attackers are increasingly focusing on stealing user credentials, often using sophisticated methods to bypass security controls. In fact, the strongest predictor of a successful account takeover was whether the attacker used an already-authenticated session or a password. This is a concerning finding, as it suggests that even when users take precautions like enabling multi-factor authentication (MFA), attackers can still find ways to compromise their accounts.

**Session Hijacking: The Top Attack Method**

One of the most striking findings in the report was the prevalence of session hijacking. This type of attack involves an attacker taking control of a user’s already-authenticated session, allowing them to access sensitive information without needing to enter credentials again. According to Prophet Security, direct attacks on accounts and sessions made up about 18% of confirmed malicious activity.

The company found that attempts using passwords were usually blocked by security controls like conditional access and phishing-resistant MFA. However, attempts using an already-authenticated session succeeded repeatedly because these sessions bypassed the standard authentication checks. This is a critical vulnerability in many systems, as it allows attackers to gain continuous access to user accounts without being detected.

**Infostealers: The Primary Source of Stolen Sessions**

Another key finding in the report was the prevalence of infostealer activity, which accounted for about 23% of confirmed malicious activity. These malicious programs were mostly delivered through web browsers, not emails, and affected roughly a quarter of the investigated organizations.

Infostealers are designed to steal sensitive information from users’ computers, often by exploiting vulnerabilities in software or using social engineering tactics like phishing. In this case, attackers used compromised legitimate websites, malicious ads, sponsored search results, and fake CAPTCHA gates to deliver infostealers that bypassed automated sandboxing.

**MFA Fatigue Attacks: A Growing Concern**

The report also highlighted the growing concern of MFA fatigue attacks. These types of attacks involve an attacker sending repeated prompts from a residential proxy until the user approves, or using a combination of brute force, lockout, automatic unlock, and push bombing to register a new device.

**What You Can Do**

While the findings in this report are concerning, there is hope for improvement. By understanding these attack patterns and vulnerabilities, organizations can take steps to harden their security controls and protect user identities.

One key takeaway from this report is the importance of implementing robust authentication methods that go beyond simple passwords. This includes enabling MFA, using conditional access, and regularly reviewing and updating security policies.

Additionally, users should be aware of the risks associated with session hijacking and take steps to protect their accounts, such as regularly changing passwords, keeping software up-to-date, and monitoring account activity for suspicious behavior.

By staying informed and taking proactive measures, we can all help to reduce the risk of identity theft and other malicious activities.


Source: Bleeping Computer — 2026-09-10