Your password is the vulnerability attackers are looking for
As geopolitical tensions increasingly spill into cyberspace, the most dangerous attacks are often launched not with sophisticated malware, but through stolen credentials
16 June, 2026
TT
16
Geopolitical conflict and cyber warfare have become inseparable. When tensions rise between nations, the digital offensive begins quietly, often weeks before any physical escalation, targeting the institutions that hold economies and governments together. Critical infrastructure, financial systems, public services, and the private sector all become battlegrounds.
What is less often acknowledged is that most of these attacks do not begin with sophisticated exploits. They begin with a stolen identity.
Identity as the primary entry point
The threat environment has shifted structurally, not just in scale. State-aligned actors, criminal groups, and hacktivists increasingly share infrastructure, techniques, and even access, operating in a landscape that is high in volume, difficult to anticipate, and faster than most organizations can respond to.
What cuts across all of them is the entry point. Stolen credentials remain attackers’ preferred method, even as billions have been spent on stronger digital infrastructure. Roughly four in five breaches today are identity-driven, and credential abuse has become the single biggest growth vector across attack types, rising more than 70% year-over-year. Far from opportunistic; this is deliberate. The majority of identity-related incidents trace back to phishing and the use of stolen credentials, which often overlap as one feeds the other. Credential harvesting campaigns are established well in advance of any escalation, ready to activate when conditions shift.
Attackers love your password more than you do
A valid username and password is enough for an attacker to open the door from the inside. Traditional intrusion detection does not flag a successful login. Once inside, an attacker can move laterally, elevate privileges, and either collect intelligence quietly over extended periods or position for disruption. In confirmed incidents, access has been maintained for months before escalation.
The method is consistent across every type of attacker. Large-scale phishing campaigns target employees using lures designed to appear as internal communications, leading to credential harvesting pages indistinguishable from legitimate portals.
AI has removed whatever skill barrier previously existed. Campaigns that once required experienced social engineers now take seconds to generate, with voice cloning and language quality that eliminates the signals users have been trained to look for. More than 3.4 billion phishing messages are sent globally every day, and more than 75% of cyber breaches originate from phishing or fraudulent messages. Human-level defense alone cannot keep pace.
Why MFA is necessary but not sufficient
Multi-factor authentication improves resilience, but it does not remove the underlying exposure.
Adversary-in-the-middle frameworks now proxy authentication in real time, presenting a legitimate login page to the victim while relaying credentials and session tokens to the attacker. The victim completes a genuine MFA challenge. The attacker receives an authenticated session. If MFA can be bypassed at the protocol level without triggering detection, then adding layers to a credential-based architecture does not solve the problem.
Rethinking identity architecture
The problem is structural: passwords are vulnerable. They can be captured in transit, harvested through phishing, cracked offline, or purchased from prior breach datasets. Centralizing them in vaults does not solve this — it concentrates the attack surface, turning a single breach into exposure across every account. Organizations that continue to manage risk at the credential level are managing the symptom, not the cause.
The architectural shift that removes this exposure is the elimination of stored credentials entirely. In a passwordless model, credentials are derived cryptographically at the moment of authentication rather than retrieved from storage so there is no shared secret to intercept, and nothing persists between sessions. Phishing-resistant standards such as FIDO2 and passkeys extend this further by binding authentication to a specific device and origin through cryptographic key pairs. A phishing attempt cannot redirect or replay the authentication because the key pair is tied to the legitimate domain. The attack vector is removed at the architectural level, not mitigated at the behavioral level.
The next step for security is to go further: to architect systems where the credential no longer exists as a target.
The attack is already in progress
The campaigns are active, the techniques are documented, and the infrastructure is in place. The window between the start of a credential harvesting operation and an attacker establishing a persistent foothold is measured in hours, not days.
Continued reliance on credential-based architectures is no longer simply a technical legacy issue, but an active risk decision. The organizations that remain resilient will be those that move beyond credential dependence altogether, rethinking identity not as an authentication mechanism to be better protected, but as a core strategic control to be rearchitected. That work cannot wait for the next incident to make the case.
- Janne Hirvimies is the chief technology officer for QuantumGate.


























