Skip to main content

Aug 7, 2026

How Attackers Operate After the Login

Mick Leach, Piotr Wojtyla

Piotr Wojtyla, who leads Threat Intel and Platform at Abnormal and has tracked identity-based attack campaigns across the industry, puts the attacker logic plainly: credential acquisition is the entire objective. Everything else—lateral movement, persistence, action on target—flows from owning a single valid identity.


32% of all breaches involve stolen credentials. (Verizon DBIR 2025)


The mechanics have evolved to match. Device code phishing exploits a legitimate Microsoft authentication flow: the victim completes MFA normally, and the attacker receives the tokens. "That token, pretty much by default, allows you to maintain access to the account for 90 days," Wojtyla explains. "And it's not bound to re-authentication for MFA, anything like that." 


 

The attacker ends up operating inside the environment as a trusted identity. The authentication logs show nothing wrong.

"It's all about getting identity. It's no longer about installing malware. At the end of the day, the only thing you need to do is get access to that identity."

— Piotr Wojtyla, Head of Threat Intel & Platform, Abnormal AI

Mike Britton, Abnormal AI’s CIO, frames the same dynamic from the defender side: "Once I'm in as your account, I'm a trusted insider—and so it's much easier to pivot, much easier to lateral move." The attacker doesn't look like an attacker. They look exactly like the person whose credentials they're using.

This is the structural problem. Most identity security tooling is built to decide whether an action is permitted, not whether the identity executing it is still behaving like itself. The authentication stack confirms the credential. It has nothing to say about whether the session that follows reflects that identity's established patterns.


Adversary-in-the-middle attacks, which bypass MFA by intercepting session cookies in real time, surged in 2026—attackers stole 18.1 million API keys and authentication tokens. (callitdev.com)


Houston Hopkins, Abnormal AI's CISO, describes what that gap means operationally. The most effective attacks, in his experience, are post-authentication: a stolen token or hijacked session that looks valid on its face, with every permission check passing cleanly.

The credential is valid. The session is active. Every permission check passes. There is nothing to alert on—unless you already know what that identity normally looks like.

"The best attacks are post-MFA. You're getting a cookie, a credential, a token—it's on the machine, it can be lifted and used outside of where it was originally intended."

— Houston Hopkins, CISO, Abnormal AI

That gap runs across industries and maturity levels. Leach has had the same conversation with security teams at more than 20 enterprises in the past few months. Regardless of company size, maturity, or tooling sophistication, the finding is the same: post-authentication visibility is the gap no one has closed.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.