BeyondTrust Finds 75% of Cyberattacks Stem from Identity and Privilege Gaps

  • BeyondTrust's Phantom Labs® Research Index analyzed 400+ offensive research projects, finding 75% of cyberattacks traced back to identity or privilege issues.
  • Top root causes included credential exposure (18%), identity relationship exposure (11%), and excessive standing privileges (11%).
  • AI agent security was a major focus, with 50% of research projects centered on AI platforms and agents.
  • Coordinated vulnerability disclosures were made in OpenAI Codex and AWS Bedrock AgentCore.

BeyondTrust's findings highlight a critical shift in cybersecurity, where attackers increasingly exploit trusted relationships between identities rather than isolated vulnerabilities. This trend is particularly pronounced in AI-driven environments, where machine and AI agent identities often operate with minimal oversight. The research underscores the need for comprehensive privilege-centric security frameworks across cloud, SaaS, and on-premises ecosystems.

AI Security Risks
How the rapid deployment of AI agents as enterprise identities will impact security frameworks and compliance.
Privilege Management
Whether organizations can effectively reduce standing privileges without disrupting operational workflows.
Cloud Ecosystem Vulnerabilities
The pace at which major cloud providers like AWS and Microsoft address identity-related security gaps.