BeyondTrust Research Finds 75% of Cyberattacks Linked to Identity and Privilege Exposure

BeyondTrust has released its latest Phantom Labs Research Index, revealing that identity and privilege weaknesses remain the primary drivers of modern cyberattacks. Based on more than 400 offensive security research projects conducted over the past year, the report found that attackers are increasingly exploiting trusted relationships between users, applications, machine identities and AI agents rather than relying solely on software vulnerabilities.
According to the research, 75% of all investigations involved identity or privilege-related issues. Credential and secret exposure emerged as the most common root cause, accounting for 18% of findings, followed by identity relationships and graph exposure (11%), excessive or standing privilege (11%), identity misconfiguration (10%) and lateral movement (6%). BeyondTrust noted that these weaknesses rarely occurred in isolation, with standing privilege and privilege escalation frequently appearing together, while exposed credentials often amplified other security issues.
“As organizations connect human, machine, and AI agent identities across dispersed environments, attackers don’t need to find a new vulnerability. They’re looking for the next identity relationship that leads to privileged access, and figuring out where those relationships create real exposure has become one of the harder problems in enterprise security today,” says Jonathan Johnson, Sr Manager, Research at BeyondTrust. “That’s exactly what we saw across our research this year: three out of four projects traced back to identity or privilege in some form, and standing privilege and privilege escalation showed up together more often than any other combination we tracked.”
The report also highlights the rapid emergence of AI agents as enterprise identities. AI and large language model (LLM) security accounted for half of all Phantom Labs research projects during the year, covering cloud AI platforms, agentic AI systems, model and data security, prompt injection techniques and AI-specific privilege escalation. BeyondTrust warns that AI agents are increasingly authenticating to enterprise systems, accessing sensitive data and inheriting permissions in much the same way as human or machine identities, often without equivalent governance or oversight.
BeyondTrust’s research also led to coordinated vulnerability disclosures involving OpenAI Codex and AWS Bedrock AgentCore, demonstrating that identity, privilege and trust assumptions continue to underpin security risks even within emerging AI ecosystems. Outside AI, the research most frequently referenced AWS, Microsoft Entra ID/Azure, GitHub, Okta and Salesforce, highlighting the prevalence of identity-related risks across cloud, DevOps and SaaS environments.
The findings have also influenced BeyondTrust’s product development, with research integrated into its Identity Security Insights® platform alongside published research and coordinated vulnerability disclosures, enabling organisations to identify and mitigate privilege-related risks before attackers can exploit them.



