Phantom Labs research reveals how identities, permissions, and AI agents are becoming the primary pathways for attackers across modern enterprise environments
Identity and privilege management have emerged as the most critical battlegrounds in cybersecurity, according to new research from BeyondTrust’s Phantom Labs. The company’s latest research reveals that three out of every four cyberattack investigations conducted over the past year were linked to identity-related or privilege-related security weaknesses, highlighting a shift in attacker behavior as organizations increasingly embrace cloud platforms, SaaS applications, machine identities, and AI-powered systems.
The findings come from an analysis of more than 400 offensive security research projects carried out by Phantom Labs. The research suggests that cybercriminals are moving away from relying solely on software vulnerabilities and are instead exploiting the trusted relationships that exist between users, applications, systems, machine accounts, and AI agents.
According to the study, 75 percent of investigated security issues involved identity or privilege exposure in some form. The report found that the majority of attacks could be traced back to a small group of recurring root causes, including credential and secret exposure, identity relationship vulnerabilities, excessive privileges, identity misconfigurations, and lateral movement opportunities.
Among these, credential and secret exposure accounted for 18 percent of findings, making it the most common issue identified. Identity relationship and graph exposure, as well as excessive or standing privileges, each represented 11 percent of findings, while identity misconfigurations accounted for 10 percent. Lateral movement techniques contributed an additional 6 percent.
“Attackers don’t need to find a new vulnerability anymore. They’re looking for the next identity relationship that leads to privileged access, and that has become one of the hardest challenges in enterprise security today.”
Jonathan Johnson, Senior Manager, Research, BeyondTrust
Researchers noted that these issues rarely occurred in isolation. In many cases, attackers combined multiple weaknesses to move through environments, escalate privileges, and gain access to critical systems. Standing privileges and privilege escalation were among the most frequently interconnected risks identified during investigations, while exposed credentials often served as the initial entry point for broader attacks.
The report highlights a growing challenge facing modern enterprises: the explosion of identities across digital environments. Organizations today manage not only human users but also machine identities, applications, APIs, cloud services, automated workflows, and increasingly autonomous AI agents. Each identity introduces new connections, permissions, and trust relationships that attackers can exploit if not properly governed.
One of the most significant areas of focus within Phantom Labs’ research was artificial intelligence and large language model security. AI-related investigations represented approximately half of all research projects conducted during the year.
Researchers explored a wide range of AI security topics, including cloud AI platforms, AI agents and agentic systems, model and data protection, prompt injection attacks, jailbreak techniques, and AI-specific privilege escalation scenarios. The findings suggest that AI systems are rapidly becoming full-fledged enterprise identities with the ability to authenticate to systems, access sensitive information, invoke applications, and perform actions across business environments.
As organizations deploy agentic AI capabilities into workflows and operations, these digital entities increasingly inherit permissions and privileges similar to those granted to human users. However, many enterprises lack the visibility and controls necessary to govern AI identities with the same rigor applied to employees and contractors.
The research also resulted in coordinated vulnerability disclosures involving emerging AI ecosystems, including findings related to OpenAI Codex and AWS Bedrock AgentCore. These discoveries reinforced a broader pattern identified throughout the study: many next-generation AI platforms continue to inherit the same underlying security assumptions around identity, access, privilege, and trust that have historically affected traditional enterprise systems.
The issue extends far beyond AI environments. Across all Phantom Labs investigations, technologies associated with cloud computing, identity management, DevOps, and SaaS platforms appeared frequently. Services from providers including AWS, Microsoft Entra ID, Azure, GitHub, Okta, and Salesforce were regularly referenced during research activities, illustrating how identity-related risks cut across virtually every layer of modern enterprise infrastructure.
BeyondTrust believes the findings reflect a fundamental change in the cybersecurity landscape. Attackers are increasingly targeting relationships rather than individual systems. Instead of searching only for software flaws, adversaries are mapping pathways between identities and identifying opportunities to inherit or escalate privileges through trusted connections.
The company argues that this trend requires organizations to rethink traditional cybersecurity strategies. Protecting credentials alone is no longer sufficient. Security teams must gain visibility into how privileges are assigned, inherited, and used across environments while continuously monitoring identity relationships that could become attack paths.
As enterprises continue adopting cloud services, automation platforms, and AI agents, managing identity-related risk is expected to become an even greater priority. The research suggests that organizations capable of reducing standing privileges, limiting unnecessary access, enforcing least-privilege principles, and understanding identity relationships will be better positioned to defend against increasingly sophisticated cyber threats.
The findings reinforce a growing industry consensus that identity has become the new security perimeter, and privilege remains the most valuable target within it.
