Identity was the target in roughly half of all confirmed malicious activity last quarter, and the strongest predictor of a successful account takeover was whether the attacker used a password or an already-authenticated session. Passwords ran into conditional access. Sessions walked past it.
Inside the report:
-
The full determination breakdown across 4.7 million questions asked of customer environments, at a median of 35 questions per investigation
-
A single account takeover reconstructed step by step, from the first login to the artifact that made a password reset irrelevant
-
Complete hardening recommendations for all four findings: session and token revocation, continuous access evaluation, cookie-store alerting, DMARC, agent-coverage reconciliation
-
How the AI SOC analyst reached each determination, including the questions that reframed the alert
-
Where AI developer tooling is now producing false positives that look like attacker tradecraft
-
Method and limitations in full, including what is excluded and why
*This report was produced from data pulled May–July 2026.
