Device Type: 
Skip to Main Content Skip to Main Content

8 Identity Attacks Hurting Businesses Today

Bad actors are getting sophisticated with AI to conduct identity-based fraud. But the same mobile network infrastructure they're trying to exploit is exactly where they can be stopped.

Author
Senior Writer
August 03, 2026
Developer Team Discussing Coding Project, Tech Professionals Collaborating at Computer During Software Project Review.
LISTEN • 10 Minutes

Key Takeaways

  • Bad actors like the low-effort and high-reward element of identity-based fraud attacks.

  • Identity-based fraud ranges from simple password attempts to intercepting authentication tickets.

  • Enterprises need to know the common types of identity-based fraud plus the tools, systems, and workflows to fight back.

Identity-based attacks exploit stolen, forged, and misused login credentials to gain access to financial and other important personal data. For many bad actors, identity attacks are their fraud of choice because of the low-effort and high-reward element. In fact, some 80% of cyberattacks use identity-based attack methods. 

Now, the bad actors are weaponizing AI to efficiently scale these nefarious activities. It’s important for enterprises to know the common attacks plus the tools, systems, and workflows to fight back.

“Identity-based attacks have become the primary playbook for bad actors across every industry,” said Adam Weir, senior manager, product marketing, at Vonage. “AI has turned what used to be manual, targeted attacks into automated campaigns that can hit thousands of businesses simultaneously. The good news is that the same mobile network infrastructure attackers are trying to exploit is exactly where we can stop them — silently, before the damage is done.”

Common attacks impacting businesses and consumers

These eight attacks range from low-tech “spraying” to sophisticated exploits:

1. Password spraying

This simple attack starts with a list of usernames. Then the bad actors use common passwords — such as “P@ssw0rd” or “12345678” — to try to log in and gain account and system access.

2. Phishing and social engineering

Phishing is one of the most common identity-based attack methods, where email messages or phone calls are used to acquire sensitive information such as login credentials and credit card numbers. These attacks come in various forms and are designed to make users believe they are receiving a valid request and engaging with a trustworthy source:

  • Email phishing: Impersonates legitimate organizations

  • Spear phishing: Targets specific individuals with personalized messages

  • Whaling: Focuses on high-profile executives

  • Voice phishing or vishing: Uses phone calls to extract information

  • SMS phishing or smishing: Leverages text messages to deceive victims

Social engineering tactics tap into urgency, fear, or impersonation to bypass traditional security measures. Fraudsters also use AI tools to remove grammatical errors that once earmarked phishing emails. AI powers bots to interact with security systems and adapt next steps based on system responses.

“Reactive security isn't enough anymore. Enterprises need tools that are already watching, already analyzing, and already blocking — before the attacker gets a foothold."

— Adam Weir, Senior Manager, Product Marketing, Vonage

3. Credential stuffing

This is when bad actors use stolen login credentials from one system to try to access an unrelated system. These credentials normally come from a data breach or were purchased on the dark web. From there, bad actors automate next steps — such as through a botnet — to log into multiple accounts at the same time. The bot can confirm if access was granted to any subsequent accounts and gather even more personal and banking data. Why is credential stuffing popular and successful? Because 65% of users reuse passwords across sites.

4. Man-in-the-middle (MITM) attack

A bad actor stands as the “man in the middle” between two parties, which can be people, systems, or a combination of the two. The parties think they are directly communicating with each other — when in fact, the bad actor is eavesdropping to collect personal data, passwords, or banking details. The man in the middle can even try to convince victims to change login credentials, transfer funds, etc.

The window between an attack starting and real damage being done has shrunk dramatically, said Weir at Vonage. Attackers use bots and AI to move fast — credential stuffing campaigns can run through millions of combinations in minutes, and man-in-the-middle attacks can harvest session data before anyone notices. 

“That's why reactive security isn't enough anymore,” he added. “Enterprises need tools that are already watching, already analyzing, and already blocking — before the attacker gets a foothold."

5. Kerberoasting

Kerberos is a network authentication protocol used to protect users in a network. Kerberoasting is a cyberattack that exploits the protocol. Bad actors request and steal service tickets that are encrypted with the password hash of network service accounts. They then crack these tickets offline to obtain the plaintext password. From there, they can impersonate the account owner.

6. Silver ticket attack

A silver ticket is a forged Kerberos service ticket created by an attacker who has stolen a service account's password hash. With the forged silver ticket in hand, bad actors can run code as the targeted local system. They can then elevate their privileges on the local host and start moving laterally within the compromised environment or even create a “golden ticket.” This gives them access to more than the originally targeted service and is a tactic for avoiding cybersecurity prevention measures.

    “What gives me confidence is that the most powerful fraud-fighting tools now operate at the mobile network level — a layer attackers simply cannot fake.”

    — Adam Weir, Senior Manager, Product Marketing, Vonage

    7. Golden ticket attack

    Bad actors like to swing big and a golden ticket attack focuses on an enterprise’s domain by accessing user data stored in a Microsoft Active Directory (AD). The attack exploits weaknesses in the Kerberos identity authentication protocol, which is used to access the AD, to help bad actors bypass normal authentication.

    8. Pass-the-hash attack

    A password hash is designed to turn a password into an unintelligible series of numbers and letters. A pass-the-hash attack takes a stolen “hashed” user credential — often accessed through social engineering — to create a new user session on the same network. Once bad actors gain access, they use various tools and techniques that scrape the active memory to derive data that will lead them to the hashes.

    Once bad actors gain full system access, they impersonate users across multiple applications. This type of hash harvesting allows them to access more areas of the network, add account privileges, target a privileged account, and set up backdoors and other gateways to enable future access.

    "What gives me confidence is that the most powerful fraud-fighting tools now operate at the mobile network level — a layer attackers simply cannot fake,” said Weir at Vonage. “They can steal passwords, forge tickets, and intercept OTPs. But they can't spoof a SIM, replicate a device's network connection, or bypass a silent authentication check tied directly to a carrier. That's the frontier of identity protection, and it's where the battle is being won."

    Make your mobile data spoof-proof

    Your customer communications are critical. Protect your business with carrier-derived phone number intelligence.

    How to combat identity-based attacks

    Any preventive measure can have a positive influence. For example, to defend against phishing attacks, organizations should implement email filtering, employee security awareness training, and advanced identity verification techniques like multi-factor authentication (MFA) and behavioral analytics. Other techniques to fight identity-based attacks include:

    Implement identity and access management (IAM) systems

    These systems commonly use single sign-on to securely authenticate users and grant access to data and applications. This provides centralized access, which makes it easier to enforce security policies. The single sign-on also reduces password fatigue. IAM systems focus on how, where, and what users can access, even after successfully completing their login.

    Train employees to recognize threats

    Your employees can offer front-line security and guard against fraudulent activity. This can be as simple as having them question and verify unusual requests, particularly when involving money transfers, credentials, or sensitive information. There’s no harm in being cautious, so empower your staff to pause any activity and then initiate a chat with the customer or bring in a manager for further review.

    Communicate regularly with customers

    Your customers may freely engage with you over any combination of phone, email, chat, and video. Their comfort to do so, on their terms, builds inherent trust. Build on this trust by reminding them to stay vigilant when logging in. Repeat these details over their favorite channels and emphasize your security procedures — such as never asking for a full Social Security Number or account password.

    Businesses can also effectively communicate with customers through branded messaging (RCS) and branded calling. Customers immediately see the company name, logo, and even reason for the outreach — which further strengthens the trust — before reading the message or answering the call.

    Use APIs to defend at the mobile level

    Network APIs are tools that help developers build applications that communicate directly with mobile carrier networks to access advanced, 5G-powered capabilities. These enable next-gen mobile identity and fraud protection without compromising user experience. For example, enterprises can verify user identities through their mobile network operators and smartphone data connection. These details cannot be spoofed. This silent authentication also removes the risk of one-time passwords that are easily intercepted and require user participation.

    Adopt a Zero Trust philosophy

    Zero Trust has quickly evolved to become a universal security standard for enterprises. It centers on a key question: Who is trying to access what, from where, and under what conditions? Combining this with network-powered solutions creates a security model that is real-time, context-aware, and invisible to the user. Now a bank can detect a SIM swap and silently trigger a step-up authentication or block access without requiring the user to enter a code.

    How to find your fraud-fighting partner

    No enterprise should take on the bad actors alone. That’s why you need a partner with experience in fighting fraud across geographies and industries. A good partner can provide AI-powered tools and mobile network partnerships to protect your business and customers, no matter if you’re behind a desk or on the road. This should include developer resources and API capabilities to help you build a tailored solution … or in-house teams to design and build your fraud-fighting strategy.

    Shield your business against rising fraud attacks

    Next-gen tools from Vonage can future-proof your end-to-end protection so you can guard your business — and protect your customers — against fraud.

    Frequently asked questions about identity-based fraud

    Select to expand or collapse this FAQ answer.

    Identity-based attacks exploit stolen, forged, and misused login credentials to gain access to financial and other important personal data. This can be as simple as taking a list of usernames and then using common passwords to try to log in and gain account and system access. Identity-based attacks can also use AI for scale and automation.

    Select to expand or collapse this FAQ answer.

    It starts with accessibility, as fraudsters can access login credentials from a data breach or purchase them on the dark web. Then consider that 65% of users reuse passwords across sites. It’s no wonder that fraudsters prefer the low effort and high reward of identity-based attacks.

    Select to expand or collapse this FAQ answer.

    Network APIs enable next-gen mobile identity and fraud protection without added steps. For example, enterprises can silently authenticate users through their mobile network operators and smartphone data connection. These details cannot be spoofed. Silent authentication also removes the risk of one-time passwords that are easily intercepted and require user participation.

    Recent Posts