How attackers compromise user accounts – and how to stop them

Identity attacks are now the single most common cause of cloud breaches, and Microsoft 365 tenants remain prime targets due to their rich access, broad permissions, and deep integration with business operations.

Iain Williamson

Iain Williamson

|

Practice Lead, Cloud Platform & Security

Posted on: February 4, 2026

|

Last updated: February 5, 2026

|

8 min read

Iain Williamson

Iain Williamson

|

Practice Lead, Cloud Platform & Security

Posted on: February 4, 2026

|

Last updated: February 5, 2026

Read time: 8 minutes

How attackers compromise user accounts - and how to stop them

Statistics show that phishing attacks are still one of the most successful attack methods against businesses and individuals.

The UK government’s Cyber Security breaches survey 2025 revealed that 93% of UK businesses that experienced a breach reported phishing attacks as the common cause and 56% were breached despite Multi-Factor Authentication (MFA).

Human error contributes to 60% of security breaches, according to the Verizon Data Breach Investigations Report (DBIR) 2025.

Human error contributes to 60% of security breaches

There’s often a perception that attacks only happen to large organisations, but whether you have 10 users or 10,000, if there’s a viable route into your environment, attackers will find it.

Identity or user attacks are so popular because:

  • They require less investment
  • The tools are widely available online
  • They don’t rely on exploiting firewalls, operating systems, or applications
  • Most modern applications live on the internet
  • Users and devices are constantly moving

This makes identity-based attacks easy and effective.

How security used to work and why that has changed

Historically, organisations focused on configuring firewalls, protecting user devices, patch management and malware detection. And while these controls are still important, they don’t protect your identities/users.

Attackers have shifted away from infrastructure-based attacks toward identity-based attacks because they are faster to execute, less expensive, more successful and easier to scale.

The weak link is no longer the technology, but user behaviour.

What Identity Attacks look like today

Modern attacks rely on social engineering. The goal is to trick users into:

  • Clicking a link
  • Signing in to a fake service
  • Granting application permissions
  • Approving an MFA request

Some common techniques include:

  • OAuth consent attacks that request access to email, calendar, or Teams data
  • MFA fatigue, where users are bombarded with authentication prompts until they approve one just to make it stop

These attacks don’t trigger traditional alerts because they look like legitimate user sign-ins. The attacker simply signs in rather than breaking in. Security experts no longer speak of a ‘hack’, but rather an ‘attack’.

Whatever data a user can access, an attacker can access too.

Why are these attacks so effective?

Identity attacks are low skill, high reward.

AI has made them even easier by enabling attackers to gather publicly available information from websites, LinkedIn, forums, and GitHub. They can build detailed profiles of users and organisations. AI helps them to improve language quality in phishing emails and run attacks at scale with minimal effort.

Once attackers gain access, they can:

  • Read emails and Teams messages
  • Access shared mailboxes and SaaS applications
  • Search for sensitive information like invoices, salaries, or credentials
  • Identify high-value users such as executives or administrators
  • Move laterally across tenants and partner organisations

Ransom attacks have shifted from encrypting files to data exfiltration and tenant lockout, which is harder to recover from in cloud environments.

Demonstration of a simple Identity Attack

In this demo, we follow an employee named Alex as he suffers and Identity Attack.

Best practices to reduce the risk of an Identity Attack

People will make mistakes, so security must be built into the platform by design.

Workforce awareness

  • Regular security awareness training.
  • Share free resources from the National Cyber Security Centre.
  • Perform phishing and attack simulations or use built-in Microsoft 365 attack simulation campaigns. These help organisations understand risk levels and improve user awareness over time.

Tenant security

  • Review and restrict OAuth application consent and approvals processes.
  • Review email security policies and phishing filters. Defender for Office 365 will capture phishing emails and quarantine them.
  • Use Conditional Access to detect:
    • Impossible travel
    • Unusual locations
    • MFA strength
  • Review guest access and cross-tenant exposure

Admin accounts

  • Remove standing admin privileges. Even dedicated admin accounts should not possess permanent high-level privileges. By using Privileged Identity Management (PIM), administrators sign in with minimal access and elevate their roles only when necessary. Once the task is complete or the time limit expires, these elevated permissions are automatically revoked.
  • Use phishing-resistant MFA instead of traditional MFA (i.e. Windows Hello for Business, passkeys, etc.)

User accounts

  • Complete an access and permission audit to reduce the blast radius of a compromised account.
  • Plan for phishing-resistant MFA for all users.
  • Start with pilot groups and executives, gather buy-in and momentum to reduce friction.

If you are interested in a chat or have any specific questions about how to protect your users from phishing attacks, feel free to request a call with me.

Last updated 5 Feb 2026

About the Author: Iain Williamson

Iain Williamson
As a Practice Lead at Intelogy, Iain brings together technical expertise, strategic vision and hands-on experience to shape and deliver modern workplace and security solutions across Microsoft 365. His role goes beyond solution delivery, taking an active role in setting technical direction, guiding delivery teams and ensuring our offerings align with evolving client needs and Microsoft’s roadmap.

Table of contents

Get Industry Insights

Subscribe to stay up to date with Microsoft 365 news and technology

Go to Top