Identity and privilege have become the dominant drivers of cyber-attacks, according to BeyondTrust’s newly released 2026 Phantom Labs Research Index, which found that 75 percent of more than 400 offensive security investigations conducted over the past year involved identity or privilege-related issues.
The report found that attackers are increasingly exploiting trusted relationships between users, applications, machine identities and AI agents rather than relying solely on software vulnerabilities. Credential and secret exposure was identified as the most common root cause, accounting for 18 percent of investigations, followed by identity relationships and graph exposure (11 percent), excessive or standing privilege (11 percent), identity misconfiguration (10 percent) and lateral movement (six percent).
“As organizations connect human, machine, and AI agent identities across dispersed environments, attackers don’t need to find a new vulnerability. They’re looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today,” said Jonathan Johnson, Senior Manager, Research at BeyondTrust. “That’s exactly what we saw across our research this year: three out of four projects traced back to identity or privilege in some form, and standing privilege and privilege escalation showed up together more often than any other combination we tracked.”
The report also highlights the growing role of AI in enterprise security. AI and large language model (LLM) security accounted for half of all Phantom Labs research during the year, with cloud AI platforms representing 58 percent of projects and AI agents and agentic systems accounting for 42 percent.
BeyondTrust said AI agents are increasingly functioning as enterprise identities by authenticating to systems, accessing data and inheriting permissions, often with less oversight than human users. The report also references coordinated vulnerability disclosures involving OpenAI Codex and AWS Bedrock AgentCore, highlighting how identity and privilege remain central security challenges across emerging AI platforms.






Discussion about this post