Identity as the New Perimeter
In today’s cyber landscape, remote and hybrid working have become firmly established across a wide range of businesses. As a result, threat actors have adapted to this new reality, leading to a growing range of techniques and attack vectors targeting Software-as-a-Service (SaaS) and cloud environments, where the traditional network perimeter offers little protection.
In hybrid and cloud environments, identity has become the primary control point governing access to corporate networks and resources. As users increasingly log-in from home networks, personal devices, and locations that may change daily, the one constant is the identity they carry with them. Once an identity is compromised, an attacker can move between platforms, access sensitive information, and operate using legitimate credentials, often without needing an exploit or malicious payload. This makes identity both a critical control point for defenders and an attractive target for threat actors seeking initial access.
Darktrace's Annual Threat Report 2026 describes identity as the “new perimeter”, noting that identity compromise and trust exploitation have emerged as dominant attack vectors. Armed with legitimate credentials, attackers are able to log in, live off the land, and remain undetected until they are ready to act. The following investigation illustrates how identity-centric attacks can provide access to multiple business-critical platforms without the need for malware or exploits.
Identifying an Identity Compromise with Darktrace
Earlier this year, Darktrace investigated a compromise in which a threat actor gained access to a customer Microsoft 365 account and used it to reach data stored across both Microsoft 365 and Salesforce. The initial account was compromised and subsequently contained by Darktrace within approximately 20 minutes. Three days later, the attacker returned, compromised two additional SaaS accounts within two and a half hours, and collected data for around six hours. At no stage did this intrusion involve malware or an exploit, demonstrating how access to a trusted account can remove the need for many of the traditional techniques associated with cyber-attacks.
Day 1: The first account

Initial Intrusion
The intrusion began with a password reset rather than a stolen password. The attacker used Microsoft Entra ID's Self-Service Password Reset (SSPR) feature to request a new password for the initial compromised account. The request came from commodity virtual private server (VPS) infrastructure, which threat actors commonly use to obscure the true origin of their connections. SSPR sends a verification code by SMS to the account owner's phone, meaning the reset could only succeed if the attacker obtained that code. The entire sequence was completed within three minutes.
Further investigation revealed that the compromise followed a voice-based social engineering attempt, suggesting the user was persuaded to share the SSPR verification code over the phone. SSPR is designed to reduce helpdesk workload; however, when its verification step can be talked out of an end user, the process becomes a direct route to account takeover. In this case, a security control intended to protect the account instead exploited what is often the weakest link in any environment: the end user.
Within seconds of logging in, the attacker registered a new device to the organization's Entra ID tenant and gave it a generic name in the format “WINDOWS-XXX”. A registered device gives an attacker a persistent foothold that access policies may treat as a known, trusted system. As soon as the attacker logged in, Darktrace identified the unusual activity, recognizing that the sign-in originated from a location and infrastructure highly unusual for the user. Darktrace also drew on additional context from Microsoft Entra ID Protection, which had also flagged the sign-in as risky. Within a minute, the same identity was used to access the organization’s Salesforce environment through single-sign on (SSO), illustrating how a single compromised account can become a gateway to multiple business-critical platforms.

Just minutes later, the attacker began downloading files from SharePoint in volumes far outside the user's normal behavior and searching for files containing passwords. Darktrace's Autonomous Response capability responded within minutes, disabling the account and terminating active sessions. Subsequent sign-in attempts were also blocked, preventing the attacker from re-establishing access.

Day 4: Reemergence and new compromised accounts

Three days later, signs of the threat actor had resurfaced. Rather than attempting to reuse the now-contained account, they repeated the same technique against new users. Two reset attempts failed when the targeted users cancelled the verification process before completion. Resets against two other accounts, however, succeeded, each again verified by SMS. The consistency of this activity indicates the attacker likely used the same vishing technique against each user, relying on social engineering to facilitate account takeover.
Each successful compromise followed the same pattern: a password reset, a successful login, the registration of a new device with a generic name, and then unauthorized access to and exfiltration of files. The third account signed in from the same device the attacker had registered under the second account, and from the same VPS infrastructure used against the first account three days earlier. Together, these indicators tie all three compromises to a single attacker-controlled machine.
Darktrace identified the second account's login as coming from a previously unseen endpoint within the same hosting infrastructure and identified unusual multifactor authentication (MFA) activity. Here the attacker had already obtained the SMS verification code during the password reset process, limiting the protection MFA could provide. The attacker immediately began browsing SharePoint libraries, running searches, and previewing files. Within two minutes, this reconnaissance activity turned into data collection.
Around two hours later, the third account followed the same sequence. Rather than moving between devices, the attacker moved between SaaS identities, highlighting how identity-centric intrusions can evade traditional network-focused monitoring.

Accomplish Mission
The data gathering activity observed was extensive and deliberate. Across the three compromised accounts the attacker exfiltrated tens of thousands of files over a period of roughly six hours. The threat actors searched SharePoint for terms such as passwords, contracts, NDAs, licenses, VPN, social security numbers, and driver's license numbers, indicating a clear interest in credentials and sensitive person information. The files accessed covered a broad range of corporate data, including billing reports, invoice listings, timesheet exports, prebilling summaries, and claims documentation. The attacker also accessed finance-related emails in the users’ mailboxes and returned to Salesforce from the registered device. Darktrace also identified multiple instances of files being modified, suggesting the intrusion extended beyond data theft to the manipulation of corporate data.
How Identity Compromises Evade Traditional Detection
This attack relied entirely on legitimate infrastructure throughout the intrusion. Tools relying on signatures, sandboxing, or indicator matching would have had little to detect, because there was no malicious payload to find.
Darktrace, however, was able to contain the initial account within minutes of the attacker beginning to collect data, disabling the user and terminating active sessions, and a later attempt to sign back in was blocked. When the attacker resurfaced using new identities a few days later, Darktrace's Real-Time AI Analyst autonomously investigated the activity and linked the seemingly separate events into a single picture of the compromise. It identified the indicators of account takeover, including identities performing an unusually high volume of operations across cloud resources in a short period of time and access to widely shared files containing sensitive information.
Shortly after the incident, the customer raised a Security Operations Support ticket, through which Darktrace analysts provided a full synopsis of the compromise. Darktrace’s Security Operations Support is a 24/7 service delivered by Darktrace’s global Security Operations Centre (SOC), providing immediate support from expert Cyber Analysts.
Conclusion
This compromise crossed two SaaS platforms and three identities, resulted in the exfiltration of tens of thousands of files, and began with a phone call. Hybrid and remote workforces require behavioral monitoring across every identity, including home, hybrid, and temporary accounts, not just devices connected to the corporate network. Self-service password resets and device registrations deserve the same scrutiny as any other privileged action, particularly when an unusual successful login follows. Verification methods that a user can simply read aloud to a caller, such as SMS codes, offer limited protection against a determined social engineer. Finally, autonomous containment is only as effective as its coverage. Containing the first affected identity should never be taken to mean the intrusion is over.
Credit to Andre Davidian (Senior Cyber Analyst), Dylan Hinz (Associate Principal Analyst)
Edited by Ryan Traill (Content Manager)
References
1. https://www.darktrace.com/resources/annual-threat-report-2026


















