The images in this article were generated with artificial intelligence. How we publish
The problem is not that companies ignore multifactor authentication or anti-phishing defenses, but that attackers have evolved into a model where stealing or supplanting legitimate identities is more cost-effective and much more silent. A live seminar will be held on 8 July 2026, organized by BleepingComputer where industry experts will analyse why traditional controls often detect these intrusions too late and how the A-driven behavior analysis can accelerate detection and response; it is a sign that companies must rethink not only what technologies they implement, but how they integrate them into automated response processes.
In modern accountability incidents there is no clear binary between "normal" and "malicious": valid credentials, trust devices and legitimate cloud services are used to pivote within corporate environments. Therefore, the alerts based on rigid signatures or thresholds generate noise and require manual investigations that consume hours or days, sufficient time for the attacker to exfilter data or establish persistence. The key is to detect contextual deviations in behavior, not just identifying known malicious artifacts.

Behavioral analytics help to build this context: by comparing mail sending patterns, login routes, interaction with documents and collaborative behavior against a base line by user, equipment and organization, it is possible to prioritize anomalies more likely to be real commitment. But the IA is not a panacea; its real value appears when it feeds automated workflows that enrich evidence, perform precautionary actions (such as forcing reauthentication, blocking suspicious sessions or isolating mailboxes) and document decisions for audit and subsequent mediation.
From a tactical perspective, there are several levers of immediate impact that organizations can act without relying only on new tools. Implement phishing-resistant MFA (FIDO2, passwords or device certificates) reduces the effectiveness of credentials exchange and SMS code interception attacks. Strengthening conditional access policies and managing privileges with less privileged principles and temporary access sessions limits the scope of a committed account. In addition, basic email controls such as SPF, DKIM and DMARC help to reduce external supplanting, although they do not protect against a legitimate compromised mailbox.
Early detection requires visibility: centralized log-in, mail and collaboration telemetry, third-party service analysis and OAuth tokens monitoring and service accounts. Without data there is no behaviour to model, so it is essential to invest in quality telemetry, keep it long enough for forensic analysis and enrich events with threat intelligence and organizational context. Complementing EDR / XDR with identity and mail signals allows the attacker to correlate actions in different layers.
Automating frequent responses to the account commitment reduces the burden on analysts and shortens the attacker's stay windows. Playbooks should include repeated steps: contain the affected account, force tokens revocation, block active sessions, analyze shipping and exfiltration activity, and coordinate safe restoration. The orchestration between solutions (e.g. SOAR, mail security solutions and identity providers) transforms an alert into a chain of concrete actions that minimize exposure time.

Human factor and governance should not be underestimated: training focused on real threats such as BEC and directed phishing, paired with clear processes to report and scale suspicions, can stop many early intrusions. At the same time, organizations should adopt hygiene controls such as the rotation of credentials, the automatic deactivation of inactive accounts and regular reviews of privileged access to prevent an attacker from finding open doors.
Finally, technological investment must be accompanied by metrics and operational objectives: to measure the average time to detection, the time to containment and the number of automated investigations that are closed without human intervention. These metrics demonstrate the return of investments in behavioral analysis and automation, and adjust tactics according to the evolution of threats. For those who want to deepen identity and authentication recommendations, NIST's guidelines on digital identity are a good starting point. https: / / pages.nist.gov / 800-63-3 /, and for recent operational guides and alerts, the page of the US security agency offers practical resources https: / / www.cisa.gov.
If your organization still analyses mail alerts in isolation or delegates complete research to human analysts, attend technical forums such as the July 8 seminar and evaluate solutions that link identity, mail and automation should be a priority. The difference between a minor incident and a mass filtration is usually the detection speed and the automated response capacity., not only the presence of MFA or an antiphishing solution installed at the gateway.
Related
More news on the same subject.

Anonymous MousKIT phishing platform identified to remove Activation Lock on iPhone and iPad
Cybersecurity researchers have documented a phishing platform as a service aimed at eliminating the protection of Activation Lock from stolen iPhones and iPads, combining forged...

United States U.S. imposes sanctions on Iranian networks linked to MOIS and Mabna in the Economic Outcast operation
The U.S. Treasury Department has launched a new round of financial sanctions against networks linked to Iran, in a campaign that the U.S. authorities describe as a coordinated e...

NemoClaw operating chain exposes Olama to unauthenticated access and alters chat templates
What has happened (confirmed facts): Oasis Security researchers have published a report describing a chain of exploitation against the NemoClaw configuration that can allow a we...

CISA adds CVE-2026-21962 to KEV by remote operation in Oracle HTTP Server and WebLogic
The United States Agency for Cybersecurity and Infrastructure (CISA) has included in its catalogue Known Exploited Vulnerabilities (KEV) the critical failure traced as CVE-2026-...

IA in code generation accelerates OSS dependencies and generates security mediation debt
A recent seminar organized by ActiveState and a survey of 300 security and development leaders in companies in different sectors confirms something that many teams already notic...

They identify WordlistLoader and SynkLoader, intermediate loaders linked to access brokers for
Cybersecurity researchers have identified two new malware families - called WordlistLoader and SynkLoader - used as intermediate stages to deploy later loads and, according to p...

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating...