Identity-Centric Threats: The New Reality
The cyberthreat landscape has transformed significantly with identity-based attacks emerging as a dominant threat vector. The 2025 Identity Threat Research Report, "Identity-Centric Threats: The New Reality," presents findings from research conducted by the eSentire Threat Response Unit (TRU) on shifting tactics, how they bypass traditional cybersecurity controls, and implications on organizational security posture. Download your complimentary copy of the report.
What are identity-centric threats?
Identity-centric threats focus on compromising user identities to gain access to valuable organizational assets, rather than exploiting technical vulnerabilities in systems. This shift has led to a significant increase in identity-based attacks, which have risen by 156% between 2023 and 2025, now accounting for 59% of all confirmed threat cases in Q1 2025.
How has Cybercrime-as-a-Service impacted security?
Cybercrime-as-a-Service platforms have transformed the threat landscape by lowering the barrier to entry for cybercriminals. These platforms provide specialized services, such as Phishing-as-a-Service, which allow even those with limited technical skills to execute sophisticated identity theft campaigns. For instance, platforms like Tycoon2FA can be rented for as little as $200-300 per month, making credential theft more frequent and diverse.
What measures can organizations take against identity threats?
Organizations should rethink their security posture by assuming that identities will be compromised. This includes implementing continuous authentication verification, comprehensive credential monitoring, and rapid response capabilities for identity-based threats. Regular threat hunting for unusual sign-ins and modifications to multi-factor authentication methods is also recommended to enhance security.
Identity-Centric Threats: The New Reality
published by Custom Information Services
Since 1989, our primary objective has been to provide business lines of technology through managed services, business process consulting, ERP solutions, and custom programming.
Our managed network services range from filling the role of an elite IT department with VCIO capability to providing a fully integrated support system for clients who already employ an active IT department. The proactive approach we take to managing information technology is designed to deliver a better result for our customers.
Our ERP consulting and software implementation services are also cored strengths of CIS. Our expertise revolves around the sales, implementation, and support of Microsoft Dynamics GP and its industry-specific customizations, especially as applied to distribution and manufacturing business models. Our objective is to ensure that customers are provided with exactly the right solutions for their business requirements - now and for the future. We embrace being a partner in the true sense of the word and our success is directly tied to that of our clients.
Any decision-maker or business owner would be well served to learn our unique perspectives on technology costs and results.