Newsletter Article

Identity Has Become the Attack Path

Many of today’s most damaging intrusions do not begin with malware. They begin with a valid login.

Microsoft recently documented an attack it attributes to a threat actor it tracks as Storm-2949, in which a single compromised identity developed into a cloud-wide breach spanning Microsoft 365, Azure applications, Key Vaults, storage accounts, databases, and virtual machines. [4]

Snare Insider Newsletter Series Article

Make sure you Subscribe

How the Intrusion Unfolded

The attack began not with malware but with social engineering against Self-Service Password Reset (SSPR): the attackers impersonated IT support, persuaded targeted users to approve fraudulent MFA prompts, and used that access to reset passwords and register their own devices for persistent access.

From there, the intrusion progressed in stages that each looked, in isolation, like ordinary administrative activity:

  • Enumeration of users, applications, and cloud resources through the Microsoft Graph API using custom Python tooling.
  • Pivoting through Azure App Service publishing profiles after direct access to the primary target application was blocked by network controls.
  • Reaching an Azure Key Vault with Owner-level permissions — within four minutes, the attackers had read dozens of secrets, including database connection strings and identity credentials.
  • Using those credentials to manipulate SQL firewall rules and Storage account access settings, then exfiltrating data over several days using a custom Python script.
  • Deploying the ScreenConnect remote-access tool to virtual machines, disabling Microsoft Defender, and creating backdoor admin accounts via Azure VM extensions.

Every capability the attackers used — Graph API queries, App Service publishing, Key Vault access, VM extensions — was a legitimate, built-in feature of the Microsoft cloud. There was no exploit and no custom malware in the early stages. The intrusion succeeded because the identity had the permissions to do all of it, and because that activity blended into what privileged administrative accounts do every day.

Why Identity Investigations Are Hard

A successful authentication is not necessarily suspicious. The surrounding context determines whether it is malicious:

  • Was a password reset initiated unexpectedly, and was a new MFA method registered immediately afterwards?
  • Did the user authenticate from a new location or device, or were unusual OAuth permissions granted?
  • Did the identity enumerate users, applications, or cloud resources?
  • Were privileged roles added, or did data-download volumes suddenly increase?
  • Did the identity access systems outside its normal role?

This pattern is not confined to sophisticated cloud intrusions. Mandiant’s M-Trends 2026 found evidence of data theft in 59% of cloud compromises investigated in 2025, with voice phishing (23%), third-party compromise (17%), and stolen credentials (16%) as the leading initial-access vectors — ahead of traditional exploits (6%). The July breach reported by India’s Bank of Baroda followed the same pattern at a smaller scale: a single compromised employee email account was enough to reach customer and internal information. [3] [2]

The Logging Implication

Identity investigations require evidence from multiple layers. Authentication logs alone rarely provide the full answer — analysts need to correlate identity-provider events with endpoint, SaaS, cloud, API, application, and network activity. Priority sources should include identity providers and directory services, MFA enrolment and reset events, privileged access-management systems, cloud control-plane and audit logs, OAuth application approvals, and service principals and machine identities.

The objective is not simply to prove that an identity authenticated. It is to establish what that identity did next.

References

[2] The Record from Recorded Future News, “India’s Bank of Baroda confirms cyber incident after hackers claim data theft,” 27 July 2026.  https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident

[3] Google Cloud Blog / Mandiant, “M-Trends 2026: Data, Insights, and Strategies From the Frontlines,” 23 March 2026.  https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026

[4] Microsoft Security Blog, “How Storm-2949 turned a compromised identity into a cloud-wide breach,” 18 May 2026.  https://www.microsoft.com/en-us/security/blog/2026/05/18/storm-2949-turned-compromised-identity-into-cloud-wide-breach/

Snare Solutions
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.