S
4

Pro tip: Found out from a network admin that most breaches start from old unused accounts, not phishing emails

I was reading a Verizon DBIR report last night and it said 35% of breaches involved dormant accounts, which surprised me since I always thought phishing was the main culprit - has anyone else seen this kind of pattern in their own workplace?
2 comments

Log in to join the discussion

Log In
2 Comments
aaron884
aaron8841mo ago
Old unused accounts being the main problem? That sounds like something a vendor selling account cleanup tools would push. Sure they might be part of it, but phishing still gets people every day. Like my buddy's company lost 50k last year because a manager clicked a fake invoice link, and that account was active and used daily. Dormant accounts usually don't have the same access levels or permissions as active ones anyway. Plus most places I've seen shut down old accounts pretty fast when someone leaves. Feels like one of those stats that sounds scary but doesn't really change how you should handle security day to day.
8
lucashart
lucashart1mo ago
Yeah, that Verizon report got my attention too. Scary stuff.
0